Vulnerability Description
Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (<<EOF instead of <<'EOF') in fn-git-create-hook() at plugins/git/internal-functions:378. On git push, bash interprets the semicolon as a command separator, executing arbitrary commands as the dokku user. This vulnerability is fixed in 0.38.2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dokku | Dokku | < 0.38.2 |
Related Weaknesses (CWE)
References
- https://github.com/dokku/dokku/pull/8590Issue TrackingPatch
- https://github.com/dokku/dokku/security/advisories/GHSA-9x85-7gxq-fcr3Vendor Advisory
FAQ
What is CVE-2026-45408?
CVE-2026-45408 is a vulnerability with a CVSS score of 9.0 (CRITICAL). Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app...
How severe is CVE-2026-45408?
CVE-2026-45408 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-45408?
Check the references section above for vendor advisories and patch information. Affected products include: Dokku Dokku.