Junglewise Threat Intelligence

CVE-2026-45408: Dokku OS command injection via app name in git pre-receive hook

CVE-2026-45408 · Severity: critical · CVSS 9 · Published 2026-06-26

Technologies: Dokku. Vendors: Dokku.

Executive brief

Dokku is an open-source Platform-as-a-Service (PaaS) that helps developers deploy and manage applications using Docker. A security flaw in how Dokku handles application names allows an authorized user to execute malicious commands on the underlying server. By using a specially crafted application name during a code deployment, an attacker could gain unauthorized access to the system, potentially leading to data theft or a complete service outage.

Technical details

An OS command injection vulnerability exists in Dokku's git plugin due to insufficient validation of application names and insecure shell scripting practices. The validation regex `(^[a-z0-9][^/:_A-Z]*$)` fails to filter shell metacharacters such as semicolons, backticks, and pipes. When a user pushes to a git remote, the `fn-git-create-hook()` function in `plugins/git/internal-functions` embeds the unquoted application name into a bash pre-receive hook using an unquoted heredoc (`<<EOF`). This allows an authenticated attacker with push privileges to inject and execute arbitrary commands with the permissions of the 'dokku' user. The issue is resolved in version 0.38.2 by tightening the validation regex and quoting variables within the hook script.

Affected products

  • Dokku Dokku < 0.38.2

Timeline

  • 2026-05-10: patched: Fix merged into master branch
  • 2026-05-13: advisory: GitHub Security Advisory published
  • 2026-06-26: disclosed: CVE published to NVD

References

Related threats