Skip to content

An authenticated attacker can read any file that the Traefik process user can access (e.g., /etc/passwd

Moderate
Siumauricio published GHSA-vq94-qm94-mxp6 Jul 5, 2025

Package

docker dokploy/dokploy (Docker)

Affected versions

< 0.23.6

Patched versions

0.23.7

Description

Impact

An authenticated attacker can read any file that the Traefik process user can access (e.g.,
/etc/passwd, application source, environment variable files containing credentials and
secrets). This may lead to full compromise of other services or lateral movement.

Patches

v0.23.7

Severity

Moderate

CVE ID

CVE-2025-53375

Weaknesses

No CWEs

Credits