---
id: CVE-2025-69201
title: Tugtainer is a self-hosted app for automating updates of docker containers
summary: >-
  Tugtainer is a self-hosted app for automating updates of docker containers. In
  versions prior to 1.15.1, arbitary arguments can be injected in
  tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
vendor: quenary
product: tugtainer
affected:
  - tugtainer < 1.15.1
patched:
  - tugtainer 1.15.1
published: '2025-12-29'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69201'
references:
  - url: >-
      https://github.com/Quenary/tugtainer/commit/dbb17d843e30fd7509acf0328c913dcb42f40831
    label: security-advisories@github.com
  - url: 'https://github.com/Quenary/tugtainer/pull/88'
    label: security-advisories@github.com
  - url: 'https://github.com/Quenary/tugtainer/releases/tag/v1.15.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/Quenary/tugtainer/security/advisories/GHSA-grc3-8w5x-g54q
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0046
epssPercentile: 0.37634
ingestedAt: '2026-10-05T19:30:59.956Z'
---

## Overview

Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.

## Affected

- `tugtainer < 1.15.1`

## Remediation

Upgrade past the affected range:

- `tugtainer 1.15.1`
