CVE-2025-69201Critical· 9.8▾ MidnightTugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent POST api/command/run. Version 1.15.1 fixes the issue.
tugtainer < 1.15.1Upgrade past the affected range:
tugtainer 1.15.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87004High· 8.1Tugtainer is a self-hosted app for automating updates of Docker containers
CVE-2026-55181Critical· 9.4Tugtainer is a self-hosted app for automating updates of Docker containers
CVE-2026-55494Critical· 9.8Tugtainer is a self-hosted app for automating updates of Docker containers
CVE-2026-62308Critical· 9.1Tugtainer is a self-hosted app for automating updates of Docker containers
CVE-2025-15131Medium· 6.3A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024
CVE-2025-15132Medium· 6.3A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024