CVE-2025-69201: Tugtainer has RCE in Agent Command Execution Api
Published Dec 29, 2025
·Updated
Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent POST api/command/run. Version 1.15.1 fixes the issue.
Affected Software
2 affected components
Tugtainer Tugtainer<1.15.1
Quenary Tugtainer Docker<1.15.1
Remediation
Patch Available
Event History
Dec 29, 2025
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-69201?
CVE-2025-69201 has been classified as a high severity vulnerability due to arbitrary argument injection risk.
2
How do I fix CVE-2025-69201?
To fix CVE-2025-69201, upgrade Tugtainer to version 1.15.1 or later.
3
What versions of Tugtainer are affected by CVE-2025-69201?
CVE-2025-69201 affects Tugtainer versions prior to 1.15.1.
4
What is the impact of CVE-2025-69201?
The impact of CVE-2025-69201 is that it allows an attacker to inject arbitrary arguments into the tugtainer-agent.
5
Is there a workaround for CVE-2025-69201?
There is no official workaround for CVE-2025-69201, so updating to the secure version is recommended.