CVE-2026-54636
Critical · CVSS 9.0Dokku — OS Command Injection (CWE-78) via app.json cron plugin shell metacharacter escape
- CVSS
- 9.0
- nvd
- EPSS
- 0.27%
- 19th pct
- KEV
- No
- Class
- other
- CWE-78
Description
Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.
Search profile — drives PoC discovery
Symbols app.jsoncrondokkucron pluginDOKKU_ROOTapp.json cron commandshell metacharacterDocker container escape
Keywords CVE-2026-54636Dokku cron injectionDokku app.json command injectionGHSA-72vm-7pc2-x95wDokku cron plugin escapeDokku container breakoutDokku 0.38.7dokku/dokku cron RCEapp.json shell injection Dokku
Versions: < 0.38.7
References
Status: enriched · ingested 2026-06-27T00:00:38.000Z · profiled 2026-07-01T18:30:14.000Z