PatchSiren

Dokploy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Dokploy CVE published 2026-08-17

CVE-2026-45791

CVE-2026-45791 Dokploy password update session token issue. Dokploy administrators and users who manage user accounts and sessions within the Dokploy platform should assess exposure and verify if their instances are affected by this vulnerability. The vulnerability allows a compromised session token to remain valid for up to three days after a password change in Dokploy instances prior to version 0.29.6. [truncated]

HIGH Dokploy CVE published 2026-08-17

CVE-2026-45790

CVE-2026-45790 is a high-severity vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). The vulnerability allows a user with member:create permission to invite an account with the owner role, and a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover. This issue is fixed in version 0.29.6.

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72902

CVE-2026-72902 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), has a critical command injection vulnerability prior to version 0.29.13. This vulnerability allows authenticated users to execute arbitrary commands on local or SSH-connected target servers due to improper interpolation of the password field in the registry.testRegistry and registry.testReg [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72901

CVE-2026-72901 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability that allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host. This issue arises from improper input validation in the volumeName field, which is interpolated without quoting in packages/server/src/utils/volume-ba [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72886

CVE-2026-72886 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). The issue, fixed in version 0.29.13, allows a member with access to one application to run a supplied script as root through schedule.runManually by exploiting the schedule.create and schedule.update endpoints in apps/dokploy/server/api/routers/schedule.ts.

NONE Dokploy CVE published 2026-08-10

CVE-2026-72885

CVE-2026-72885 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is affected by a command injection vulnerability prior to version 0.29.13. The vulnerability exists in the dockerContextPath accepted by apps/dokploy/components/dashboard/application/build/show.tsx, which flows through getDockerContextPath in packages/server/src/utils/filesystem/directory.t [truncated]

HIGH Dokploy CVE published 2026-08-10

CVE-2026-72884

CVE-2026-72884 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a high-severity vulnerability allowing authenticated users to inject shell metacharacters and execute arbitrary commands on the Dokploy host. The vulnerability exists in the sanitizeCommand function in packages/server/src/utils/builders/compose.ts. This function only trims whitespa [truncated]

HIGH Dokploy CVE published 2026-08-10

CVE-2026-72883

CVE-2026-72883 Dokploy WebSocket Handler Access Control Bypass. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a high-severity vulnerability in its WebSocket handlers. This issue allows authenticated organization members to bypass access controls and gain unauthorized access to sensitive servers and services, potentially leading to root terminal access or the ability to read logs an [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72882

CVE-2026-72882 Dokploy Remote Code Execution Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability in versions 0.28.8 and earlier. This vulnerability allows authenticated users to inject shell metacharacters into filePath when creating or updating file mounts for a service, leading to the execution of attacker-controlled commands on the configured re [truncated]

MEDIUM Dokploy CVE published 2026-08-10

CVE-2026-72881

CVE-2026-72881 Dokploy Command Injection Vulnerability. Dokploy, a self-hostable Platform as a Service (PaaS), contains a medium-severity command injection vulnerability. Prior to version 0.29.13, the database backup and restore command builders interpolate database names, usernames, and passwords into nested shell command strings. An authenticated administrator with permission to create databases and con [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72880

CVE-2026-72880 Dokploy Path Traversal Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical path traversal vulnerability. This vulnerability, identified as CVE-2026-72880, allows an authenticated user with certificate create or delete permission to write attacker-controlled certificate content outside the intended directory or delete an out-of-root directory. The [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72879

CVE-2026-72879 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is vulnerable to a critical command injection issue. The getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts directly interpolates registry.password and registry.registryUrl into a shell command without proper escaping. This allows an authenticated user with projec [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72878

CVE-2026-72878 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is vulnerable to a critical command injection issue. This vulnerability allows authenticated admin/owners to inject arbitrary OS commands on the host machine running Dokploy, potentially leading to significant disruption and lateral movement within the network. The vulnerability is fixed in [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72877

CVE-2026-72877 Dokploy Remote Code Execution Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is vulnerable to remote code execution due to improper validation and interpolation of the dockerImage field. An authenticated user with application create or update permission can inject shell commands, potentially exposing host secrets and other projects. Defenders responsible for Dok [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72876

CVE-2026-72876 Dokploy Vulnerability Debrief. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a critical vulnerability allowing arbitrary command execution on another tenant's server. The issue is fixed in version 0.29.13. Administrators and users of Dokploy instances should assess exposure and apply the patch. The vulnerability is caused by a lack of activeOrganizationId ownership chec [truncated]

HIGH Dokploy CVE published 2026-08-10

CVE-2026-72875

A vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS), allows users with traefikFiles.read permission to execute arbitrary commands on a managed server through shell metacharacters. This issue is fixed in version 0.29.13. The vulnerability can lead to lateral movement, data breaches, or system compromise if not addressed promptly. Defenders should assess exposure and apply the pat [truncated]

HIGH Dokploy CVE published 2026-08-10

CVE-2026-72874

CVE-2026-72874 Dokploy Remote Command Execution Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a vulnerability in the cloneGitRepository function. This function, located in packages/server/src/utils/providers/git.ts, allows an authenticated user with application access to execute arbitrary operating system commands on the Dokploy host. This is achieved by setting a ma [truncated]

MEDIUM Dokploy CVE published 2026-08-10

CVE-2026-72873

CVE-2026-72873 Dokploy Git Provider Secrets Exposure. Dokploy, a free, self-hostable Platform as a Service (PaaS), had a vulnerability prior to version 0.29.13 that allowed users with service:read permission to retrieve Git provider secrets, including githubClientSecret, githubPrivateKey, and githubWebhookSecret. This issue was fixed in version 0.29.13. Dokploy administrators and users with service:read p [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72872

A critical vulnerability was found in Dokploy, a free, self-hostable Platform as a Service (PaaS), which allows a member with service deployment permission to execute arbitrary operating system commands on the Dokploy host or target server. This issue is due to the lack of validation in the application.saveBitbucketProvider function, which stores bitbucketOwner and bitbucketRepository without proper valid [truncated]

HIGH Dokploy CVE published 2026-08-10

CVE-2026-72871

CVE-2026-72871 Dokploy GitHub App provider insertion issue. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a high-severity issue allowing an attacker to insert a GitHub App provider containing sensitive material into another organization prior to version 0.29.13. The unauthenticated /api/providers/github/setup route trusts gh_init organizationId and userId values from the state paramet [truncated]

HIGH Dokploy CVE published 2026-08-10

CVE-2026-72870

CVE-2026-72870 Dokploy Remote Code Execution Vulnerability. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a high-severity vulnerability allowing authenticated users with project access to execute arbitrary operating-system commands as the Dokploy server process. The buildRemoteDocker() function interpolates the application-controlled dockerImage value directly into a docker pull shell [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72869

CVE-2026-72869 Dokploy backup.restoreBackupWithLogs tRPC subscription command injection vulnerability allows an authenticated user with backup:restore permission to inject arbitrary commands in the Docker-privileged host context. The issue is fixed in Dokploy version 0.29.13. Administrators and users of Dokploy instances should assess their exposure and take action to mitigate the vulnerability. This incl [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72868

A critical vulnerability was found in Dokploy, a free, self-hostable Platform as a Service (PaaS), which allows a low-privileged organization member to execute arbitrary commands in the root Dokploy container. This is due to the interpolation of sensitive fields into an rclone ls command executed through child_process.exec in the apps/dokploy/server/api/routers/destination.ts file prior to version 0.29.13.

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72867

CVE-2026-72867 Dokploy Arbitrary Host Command Execution. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability allowing low-privileged authenticated users to execute arbitrary host commands. This issue arises from an incomplete fix for CVE-2026-45628, enabling malicious custom Git branch storage. When a deployment is triggered, the stored branch is passed to shell- [truncated]

HIGH Dokploy CVE published 2026-08-10

CVE-2026-72866

CVE-2026-72866 Dokploy WebSocket Authentication Bypass. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a WebSocket handler in apps/dokploy/server/wss/terminal.ts that validates a session but does not authorize access to the requested server. An authenticated user can connect to /terminal?serverId=local, select the special serverId=local branch, and obtain an interactive terminal on the [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72865

CVE-2026-72865 Dokploy Remote Code Execution Vulnerability. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a critical vulnerability allowing authenticated members with compose write and deploy permissions to execute arbitrary operating-system commands. The vulnerability is fixed in version 0.29.13. Administrators and users of Dokploy instances should assess exposure and apply the patch [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72864

A critical vulnerability exists in Dokploy, a free, self-hostable Platform as a Service (PaaS), which allows any authenticated member to obtain a root shell in arbitrary containers on a self-hosted instance. This issue arises from inadequate authorization in the /docker-container-terminal endpoint, where the attacker-controlled containerId is not validated against the caller's role, organization, or servi [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72863

CVE-2026-72863 Dokploy WebSocket Authentication Bypass. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability in its WebSocket handlers. These handlers authenticate sessions but fail to authorize them, allowing any authenticated member to access any container on the host. This includes the Dokploy container with the Docker socket, potentially leading to root access [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72862

CVE-2026-72862 Dokploy Unauthenticated Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is vulnerable to unauthenticated command injection in its database service deployment functions. This critical vulnerability, fixed in version 0.29.13, allows attackers to inject commands via user-controlled dockerImage fields. Affected deployments should be reviewed and upd [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72740

CVE-2026-72740 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). An authenticated member with service deployment permission and an attached SSH key can execute arbitrary commands on the Dokploy host during deployment due to improper sanitization of user-controlled customGitUrl in packages/server/src/utils/providers/git.ts. This issue is fixed in version 0.29.13.