Executive brief
Dokku, a platform for deploying and managing applications, contains a flaw that leaves sensitive login credentials exposed on the server. Because of a configuration error when creating the authentication file, these credentials are saved with overly broad permissions. This allows any user with local access to the server to read the credentials, potentially leading to the theft of Git account access and unauthorized access to source code.
Technical details
A vulnerability in Dokku's git:auth command stems from the use of the bash 'touch' command to initialize the $DOKKU_ROOT/.netrc file before the netrc binary can set its own restrictive permissions. Because 'touch' respects the system's default umask (typically 0644), the file is created with world-readable permissions, bypassing the netrc binary's intended 0600 (owner-only) setting. A local attacker with shell access to the Dokku host can read this file to obtain plaintext Git credentials. The issue is resolved in version 0.38.2, which explicitly enforces 0600 permissions and repairs existing installations.
Affected products
- Dokku Dokku < 0.38.2
Timeline
- 2026-05-09: patched: Pull request #8589 merged to enforce permissions.
- 2026-05-10: advisory: Release 0.38.2 published.
- 2026-06-26: disclosed: CVE-2026-45407 published.