VU#280377: Dokploy is vulnerable to OS command injection

2026-09-17T20:52:01Z•dd93090fda4f3ab85dbb82a8ac1b212cdc69dd26a9b07058964ed508c12acff8
CVE-2025-20701CVE-2026-12780CVE-2026-84286CVE-2026-90999BluetoothCERT/CCIoTOS command injectionSecure Boot bypassUEFIdenial of servicedeserializationfirmwarekernel driverout-of-bounds memory accessphysical disk writespickleprivilege escalationprompt injectionremote code executionsupply chain

What happened

CERT/CC vulnerability notes describe multiple newly reported flaws across Dokploy, MLflow, Sentry Seer, ExLlamaV3, AOMEI Backupper, UEFI firmware, and Skullcandy Dime 3 earbuds. Impacts range from authenticated root-level OS command injection and malicious pickle remote code execution to privileged coding-agent compromise, denial of service, UEFI-level persistence, Secure Boot bypass, and unauthenticated Bluetooth pairing. Several entries include CVE identifiers and remediation guidance.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
dd93090fda4f3ab85dbb82a8ac1b212cdc69dd26a9b07058964ed508c12acff8
Enrichment time
2026-09-17T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.