CVE-2026-45408
Critical · CVSS 9.0Dokku — OS Command Injection via unquoted heredoc in bash pre-receive hook (CWE-78)
- CVSS
- 9.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-78
Description
Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (<<EOF instead of <<'EOF') in fn-git-create-hook() at plugins/git/internal-functions:378. On git push, bash interprets the semicolon as a command separator, executing arbitrary commands as the dokku user. This vulnerability is fixed in 0.38.2.
Search profile — drives PoC discovery
Symbols fn-git-create-hookplugins/git/internal-functionsinternal-functions:378<<EOF<<'EOF'^[a-z0-9][^/:_A-Z]*$pre-receivedokku user
Keywords CVE-2026-45408DokkuGHSA-9x85-7gxq-fcr3dokku RCEdokku app name injectiongit pre-receive hook command injectiondokku heredoc unquoteddokku shell metacharacterdokku 0.38.2fn-git-create-hook exploitdokku OS command injection
Versions: < 0.38.2
References
Status: enriched · ingested 2026-06-27T00:00:38.000Z · profiled 2026-07-01T12:30:14.000Z