CVE-2025-69201: Quenary Tugtainer
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.
Affected products
- Quenary Tugtainer: before 1.15.1 (fixed in 1.15.1)
Published 2025-12-29. Last modified 2026-10-07.