{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-82954/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dokploy:dokploy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-82954"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Dokploy (\u003c= 0.29.7)"],"_cs_severities":["critical"],"_cs_tags":["web-application-vulnerability","path-traversal","cve-2026-82954"],"_cs_type":"advisory","_cs_vendors":["Dokploy"],"content_html":"\u003cp\u003eDokploy versions 0.29.7 and earlier contain a critical path traversal vulnerability (CVE-2026-82954) located within the \u003ccode\u003ewriteTraefikConfigInPath\u003c/code\u003e function in \u003ccode\u003epackages/server/src/utils/traefik/application.ts\u003c/code\u003e. The flaw allows remote, unauthenticated attackers to manipulate the 'path' argument, leading to arbitrary file system access. This vulnerability permits the reading or overwriting of sensitive configuration files, which can be leveraged to gain unauthorized system control. The vulnerability is publicly disclosed, and given the nature of the software as a deployment management tool, successful exploitation carries a high risk of systemic compromise. The vendor has not provided a response or a patch as of the time of disclosure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 9.9, reflecting its critical potential for unauthorized file access and system-level impact. Attackers targeting this vulnerability can extract sensitive environment variables, credentials, or Traefik configuration files, potentially escalating access to any containerized workloads managed by the Dokploy instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web application logs for suspicious path traversal patterns (e.g., directory indexing characters like \u0026quot;../\u0026quot;) directed at Dokploy management endpoints.\u003c/li\u003e\n\u003cli\u003eApply network segmentation to ensure Dokploy management interfaces are not exposed to the public internet until a security patch is released by the vendor.\u003c/li\u003e\n\u003cli\u003eConduct an audit of the file system integrity in the Dokploy server environment to identify signs of unauthorized file modification or exfiltration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T01:01:03Z","date_published":"2026-09-01T01:01:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dokploy-path-traversal/","summary":"Dokploy versions up to 0.29.7 are vulnerable to remote path traversal via the writeTraefikConfigInPath function, allowing attackers to access arbitrary files on the system.","title":"Path Traversal Vulnerability in Dokploy","url":"https://feed.craftedsignal.io/briefs/2026-09-dokploy-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-82954","version":"https://jsonfeed.org/version/1.1"}