These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-45791 Dokploy password update session token issue. Dokploy administrators and users who manage user accounts and sessions within the Dokploy platform should assess exposure and verify if their instances are affected by this vulnerability. The vulnerability allows a compromised session token to remain valid for up to three days after a password change in Dokploy instances prior to version 0.29.6. [truncated]
CVE-2026-45790 is a high-severity vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). The vulnerability allows a user with member:create permission to invite an account with the owner role, and a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover. This issue is fixed in version 0.29.6.
CVE-2026-72902 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), has a critical command injection vulnerability prior to version 0.29.13. This vulnerability allows authenticated users to execute arbitrary commands on local or SSH-connected target servers due to improper interpolation of the password field in the registry.testRegistry and registry.testReg [truncated]
CVE-2026-72901 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability that allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host. This issue arises from improper input validation in the volumeName field, which is interpolated without quoting in packages/server/src/utils/volume-ba [truncated]
CVE-2026-72886 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). The issue, fixed in version 0.29.13, allows a member with access to one application to run a supplied script as root through schedule.runManually by exploiting the schedule.create and schedule.update endpoints in apps/dokploy/server/api/routers/schedule.ts.
CVE-2026-72885 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is affected by a command injection vulnerability prior to version 0.29.13. The vulnerability exists in the dockerContextPath accepted by apps/dokploy/components/dashboard/application/build/show.tsx, which flows through getDockerContextPath in packages/server/src/utils/filesystem/directory.t [truncated]
CVE-2026-72884 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a high-severity vulnerability allowing authenticated users to inject shell metacharacters and execute arbitrary commands on the Dokploy host. The vulnerability exists in the sanitizeCommand function in packages/server/src/utils/builders/compose.ts. This function only trims whitespa [truncated]
CVE-2026-72883 Dokploy WebSocket Handler Access Control Bypass. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a high-severity vulnerability in its WebSocket handlers. This issue allows authenticated organization members to bypass access controls and gain unauthorized access to sensitive servers and services, potentially leading to root terminal access or the ability to read logs an [truncated]
CVE-2026-72882 Dokploy Remote Code Execution Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability in versions 0.28.8 and earlier. This vulnerability allows authenticated users to inject shell metacharacters into filePath when creating or updating file mounts for a service, leading to the execution of attacker-controlled commands on the configured re [truncated]
CVE-2026-72881 Dokploy Command Injection Vulnerability. Dokploy, a self-hostable Platform as a Service (PaaS), contains a medium-severity command injection vulnerability. Prior to version 0.29.13, the database backup and restore command builders interpolate database names, usernames, and passwords into nested shell command strings. An authenticated administrator with permission to create databases and con [truncated]
CVE-2026-72880 Dokploy Path Traversal Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical path traversal vulnerability. This vulnerability, identified as CVE-2026-72880, allows an authenticated user with certificate create or delete permission to write attacker-controlled certificate content outside the intended directory or delete an out-of-root directory. The [truncated]
CVE-2026-72879 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is vulnerable to a critical command injection issue. The getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts directly interpolates registry.password and registry.registryUrl into a shell command without proper escaping. This allows an authenticated user with projec [truncated]
CVE-2026-72878 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is vulnerable to a critical command injection issue. This vulnerability allows authenticated admin/owners to inject arbitrary OS commands on the host machine running Dokploy, potentially leading to significant disruption and lateral movement within the network. The vulnerability is fixed in [truncated]
CVE-2026-72877 Dokploy Remote Code Execution Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is vulnerable to remote code execution due to improper validation and interpolation of the dockerImage field. An authenticated user with application create or update permission can inject shell commands, potentially exposing host secrets and other projects. Defenders responsible for Dok [truncated]
CVE-2026-72876 Dokploy Vulnerability Debrief. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a critical vulnerability allowing arbitrary command execution on another tenant's server. The issue is fixed in version 0.29.13. Administrators and users of Dokploy instances should assess exposure and apply the patch. The vulnerability is caused by a lack of activeOrganizationId ownership chec [truncated]
A vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS), allows users with traefikFiles.read permission to execute arbitrary commands on a managed server through shell metacharacters. This issue is fixed in version 0.29.13. The vulnerability can lead to lateral movement, data breaches, or system compromise if not addressed promptly. Defenders should assess exposure and apply the pat [truncated]
CVE-2026-72874 Dokploy Remote Command Execution Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a vulnerability in the cloneGitRepository function. This function, located in packages/server/src/utils/providers/git.ts, allows an authenticated user with application access to execute arbitrary operating system commands on the Dokploy host. This is achieved by setting a ma [truncated]
CVE-2026-72873 Dokploy Git Provider Secrets Exposure. Dokploy, a free, self-hostable Platform as a Service (PaaS), had a vulnerability prior to version 0.29.13 that allowed users with service:read permission to retrieve Git provider secrets, including githubClientSecret, githubPrivateKey, and githubWebhookSecret. This issue was fixed in version 0.29.13. Dokploy administrators and users with service:read p [truncated]
A critical vulnerability was found in Dokploy, a free, self-hostable Platform as a Service (PaaS), which allows a member with service deployment permission to execute arbitrary operating system commands on the Dokploy host or target server. This issue is due to the lack of validation in the application.saveBitbucketProvider function, which stores bitbucketOwner and bitbucketRepository without proper valid [truncated]
CVE-2026-72871 Dokploy GitHub App provider insertion issue. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a high-severity issue allowing an attacker to insert a GitHub App provider containing sensitive material into another organization prior to version 0.29.13. The unauthenticated /api/providers/github/setup route trusts gh_init organizationId and userId values from the state paramet [truncated]
CVE-2026-72870 Dokploy Remote Code Execution Vulnerability. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a high-severity vulnerability allowing authenticated users with project access to execute arbitrary operating-system commands as the Dokploy server process. The buildRemoteDocker() function interpolates the application-controlled dockerImage value directly into a docker pull shell [truncated]
CVE-2026-72869 Dokploy backup.restoreBackupWithLogs tRPC subscription command injection vulnerability allows an authenticated user with backup:restore permission to inject arbitrary commands in the Docker-privileged host context. The issue is fixed in Dokploy version 0.29.13. Administrators and users of Dokploy instances should assess their exposure and take action to mitigate the vulnerability. This incl [truncated]
A critical vulnerability was found in Dokploy, a free, self-hostable Platform as a Service (PaaS), which allows a low-privileged organization member to execute arbitrary commands in the root Dokploy container. This is due to the interpolation of sensitive fields into an rclone ls command executed through child_process.exec in the apps/dokploy/server/api/routers/destination.ts file prior to version 0.29.13.
CVE-2026-72867 Dokploy Arbitrary Host Command Execution. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability allowing low-privileged authenticated users to execute arbitrary host commands. This issue arises from an incomplete fix for CVE-2026-45628, enabling malicious custom Git branch storage. When a deployment is triggered, the stored branch is passed to shell- [truncated]
CVE-2026-72866 Dokploy WebSocket Authentication Bypass. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a WebSocket handler in apps/dokploy/server/wss/terminal.ts that validates a session but does not authorize access to the requested server. An authenticated user can connect to /terminal?serverId=local, select the special serverId=local branch, and obtain an interactive terminal on the [truncated]
CVE-2026-72865 Dokploy Remote Code Execution Vulnerability. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a critical vulnerability allowing authenticated members with compose write and deploy permissions to execute arbitrary operating-system commands. The vulnerability is fixed in version 0.29.13. Administrators and users of Dokploy instances should assess exposure and apply the patch [truncated]
A critical vulnerability exists in Dokploy, a free, self-hostable Platform as a Service (PaaS), which allows any authenticated member to obtain a root shell in arbitrary containers on a self-hosted instance. This issue arises from inadequate authorization in the /docker-container-terminal endpoint, where the attacker-controlled containerId is not validated against the caller's role, organization, or servi [truncated]
CVE-2026-72863 Dokploy WebSocket Authentication Bypass. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability in its WebSocket handlers. These handlers authenticate sessions but fail to authorize them, allowing any authenticated member to access any container on the host. This includes the Dokploy container with the Docker socket, potentially leading to root access [truncated]
CVE-2026-72862 Dokploy Unauthenticated Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), is vulnerable to unauthenticated command injection in its database service deployment functions. This critical vulnerability, fixed in version 0.29.13, allows attackers to inject commands via user-controlled dockerImage fields. Affected deployments should be reviewed and upd [truncated]
CVE-2026-72740 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). An authenticated member with service deployment permission and an attached SSH key can execute arbitrary commands on the Dokploy host during deployment due to improper sanitization of user-controlled customGitUrl in packages/server/src/utils/providers/git.ts. This issue is fixed in version 0.29.13.