Dokku Dokku — CVE-2026-54636 (Critical)

Date Jun 26, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Dokku · Dokku
CVE CVE-2026-54636
Critical vendor advisory CVE-2026-54636

Summary

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.0) in Dokku Dokku. Patch or mitigate promptly.

Operator check

Review CVE-2026-54636 in your asset inventory. Apply patches per vendor guidance and verify Dokku is not exposed. CVSS score: 9.0.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.