CVE-2025-53825: Dokploy's Preview Deployments are vulnerable to Remote Code Execution

Published Jul 14, 2025
·
Updated

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and access sensitive environment variables by simply opening a pull request on a public repository. This exposes secrets and potentially enables remote code execution, putting all public Dokploy users using these preview deployments at risk. Version 0.24.3 contains a fix for the issue.

Affected Software

2 affected components
Dokploy Dokploy<0.24.3
Dokploy Dokploy<0.24.3

Event History

Jul 14, 2025
CVE Published
via MITRE·10:44 PM
Data Sourced
via MITRE·10:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-53825?

CVE-2025-53825 is considered a critical vulnerability due to its ability to allow unauthenticated users to execute arbitrary code.

2

How do I fix CVE-2025-53825?

To fix CVE-2025-53825, upgrade to Dokploy version 0.24.3 or later.

3

What types of systems are affected by CVE-2025-53825?

CVE-2025-53825 affects all versions of Dokploy prior to 0.24.3.

4

What exploit vector does CVE-2025-53825 use?

CVE-2025-53825 can be exploited through unauthenticated preview deployments initiated by opening a pull request on a public repository.

5

What data could be compromised by CVE-2025-53825?

CVE-2025-53825 can potentially expose sensitive environment variables and allow execution of arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203