Impact
A path traversal vulnerability exists in the function that writes Traefik configuration files. By manipulating the path argument, an attacker can cause the application to read or write files outside the intended directory. The weakness is classified as CWE‑22 and can be leveraged for remote exploitation. The impact is that an attacker can read sensitive configuration files, modify or replace them, and potentially gain full control over the target system.
Affected Systems
Dokploy, versions 0.29.7 and earlier, are affected. The vulnerability resides in the Settings component of the application and affects all deployments running a vulnerable version until a patch is applied.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, and the exploit is publicly available. Although the EPSS score is not provided, the public nature of the exploit combined with the high CVSS suggests a realistic risk of remote exploitation. The vulnerability is not listed in CISA's KEV catalog, but that does not mitigate the serious risk associated with the unvalidated file path handling.
OpenCVE Enrichment