Dokku Dokku — CVE-2026-54636 (Critical)
Critical vendor advisory
CVE-2026-54636
Summary
Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.0) in Dokku Dokku. Patch or mitigate promptly.
Operator check
Review CVE-2026-54636 in your asset inventory. Apply patches per vendor guidance and verify Dokku is not exposed. CVSS score: 9.0.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.