VU#280377: Dokploy is vulnerable to OS command injection
2026-09-17T20:52:01Z•dd93090fda4f3ab85dbb82a8ac1b212cdc69dd26a9b07058964ed508c12acff8
CVE-2025-20701CVE-2026-12780CVE-2026-84286CVE-2026-90999BluetoothCERT/CCIoTOS command injectionSecure Boot bypassUEFIdenial of servicedeserializationfirmwarekernel driverout-of-bounds memory accessphysical disk writespickleprivilege escalationprompt injectionremote code executionsupply chain
What happened
CERT/CC vulnerability notes describe multiple newly reported flaws across Dokploy, MLflow, Sentry Seer, ExLlamaV3, AOMEI Backupper, UEFI firmware, and Skullcandy Dime 3 earbuds. Impacts range from authenticated root-level OS command injection and malicious pickle remote code execution to privileged coding-agent compromise, denial of service, UEFI-level persistence, Secure Boot bypass, and unauthenticated Bluetooth pairing. Several entries include CVE identifiers and remediation guidance.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- dd93090fda4f3ab85dbb82a8ac1b212cdc69dd26a9b07058964ed508c12acff8
- Enrichment time
- 2026-09-17T20:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.