CVE-2026-54636

CRITICAL

Dokku: OS Command Injection via app.json managed Cron

Title source: cna
STIX 2.1

Description

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/dokku/dokku/pull/8672

Scores

CVSS v3 9.0
EPSS 0.0027
EPSS Percentile 19.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
dokku/dokku < 0.38.7 (2 CPE variants)
Published Jun 26, 2026
Tracked Since Jun 26, 2026