Executive brief
Dockwatch, a tool used to manage Docker containers, contains a critical security flaw that allows unauthorized users to take complete control of the host server. By sending a specially crafted web request, an attacker can bypass login screens and execute administrative commands. Because this software is typically granted high-level access to the underlying system, an exploit could lead to full data theft, service disruption, or the deployment of ransomware across the entire infrastructure.
Technical details
This vulnerability consists of two chained issues: an Execution After Redirect (EAR) flaw (CWE-698) and OS Command Injection (CWE-78). In loader.php, the application fails to call exit() after issuing a location header redirect for unauthenticated users, allowing subsequent code to execute. An attacker can exploit this to reach ajax/compose.php, where the 'composePath' POST parameter is passed directly to shell_exec() via sprintf() without sanitization. By injecting shell metacharacters into this parameter, a remote, unauthenticated attacker can execute arbitrary commands with the privileges of the web server. Given that Dockwatch is commonly deployed with the Docker socket mounted, this typically results in full host compromise. A fix involving the addition of exit() calls and the use of escapeshellarg() has been proposed in the project's repository.
Affected products
- Notifiarr Dockwatch through 0.6.567
Timeline
- 2026-07-02: disclosed: Coordinated disclosure via VulnCheck
- 2026-07-02: advisory
- 2026-07-02: patched: Pull request 135 submitted to address the issue