CVE-2023-0626: Docker Desktop

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.

Affected products

  • Docker Docker Desktop: before 4.12.0 (fixed in 4.12.0)

Published 2023-09-25. Last modified 2026-06-17.