Executive brief
Dokku is an open-source platform used to deploy and manage applications. A security flaw in its OpenResty plugin allows a user with permission to push code to an application to execute unauthorized commands on the underlying server. This could lead to a complete takeover of the host system, potentially exposing sensitive data or disrupting all services managed by the platform.
Technical details
An eval injection vulnerability exists in the Dokku openresty-vhosts plugin prior to version 0.38.2. The plugin copies files from an application's 'openresty/http-includes/' directory and interpolates the filenames into a single-quoted shell string without proper escaping. An attacker with push access can craft a filename containing a single quote and command substitution syntax (e.g., `poc'$(cmd)'x.conf`) to break out of the shell quoting. When the application is next deployed, the malicious filename is processed by 'eval', leading to arbitrary command execution on the host as the 'dokku' user. The fix introduces filename validation using a strict regex and skips non-regular files during extraction.
Affected products
- Dokku Dokku < 0.38.2
Timeline
- 2026-05-09: patched: Fix merged in pull request #8588
- 2026-05-10: other: Release 0.38.2 published
- 2026-05-13: advisory: GitHub Security Advisory published
- 2026-06-26: disclosed: CVE published to NVD