dokploy/apps
Mauricio Siu 5563699f71 fix(security): enforce org-scope on swarm reads and escape nodeId
swarm.getNodes/getNodeInfo/getNodeApps/getAppInfos accepted a caller-supplied
serverId and ran remote Docker Swarm reads against it with no organization
check, exposing another tenant's swarm topology cross-org (getContainerStats
already had the check; the others did not). getNodeInfo additionally
interpolated nodeId unescaped into 'docker node inspect ${nodeId}'.

Adds an org-ownership assertion to the four unscoped handlers and passes nodeId
through shell-quote in getNodeInfo.

Closes GHSA-jj6h-388v-9rwm
2026-07-19 21:20:47 -06:00
..
api Feat/tailwind v4 shadcn update (#4706) 2026-06-30 15:45:23 -06:00
dokploy fix(security): enforce org-scope on swarm reads and escape nodeId 2026-07-19 21:20:47 -06:00
monitoring fix: enhance container metrics query to support wildcard matching for container names 2026-03-08 16:16:45 -06:00
schedules Feat/tailwind v4 shadcn update (#4706) 2026-06-30 15:45:23 -06:00