PatchSiren

Dokploy CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Dokploy CVE published 2026-08-10

CVE-2026-72739

CVE-2026-72739 Dokploy Arbitrary Command Execution Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), has a vulnerability that allows for arbitrary command execution on the Docker host. This occurs when a compose with a maliciously crafted name or service definition is deployed. The createCommand() function constructs shell commands by interpolating compose service names and confi [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72738

CVE-2026-72738 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). An authenticated user with backup:read permission can execute arbitrary commands on the Dokploy host due to improper handling of the search parameter in the backup.listBackupFiles tRPC endpoint. This issue allows for potential command execution on the host, possible lateral movement or escalation of [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72737

CVE-2026-72737 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). An authenticated member with backup permissions for a service in one organization can exploit this vulnerability to cause another organization's S3 accessKey and secretAccessKey to be materialized, read that organization's backup objects, or redirect and poison backups across tenant boundaries.

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72736

CVE-2026-72736 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). The vulnerability allows for remote code execution via shell command injection in the registry credential testing and Docker Swarm cluster management endpoints. This issue was fixed in version 0.29.13. Dokploy's vulnerability stems from passing user-controlled values directly into shell commands via [truncated]

HIGH Dokploy CVE published 2026-08-10

CVE-2026-72734

CVE-2026-72734 Dokploy Server Deletion Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a high-severity vulnerability allowing unauthorized server deletion and exposure of sensitive information. The server.remove tRPC mutation in Dokploy's apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serverId and calls several functions without verifying organiz [truncated]

CRITICAL Dokploy CVE published 2026-08-10

CVE-2026-72733

CVE-2026-72733 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). An authenticated member with backup-restore permission can inject operating-system commands that execute in the Dokploy host context through execAsync or execAsyncRemote, even when no valid database container or backup file exists. This issue is fixed in version 0.29.13.

CRITICAL Dokploy CVE published 2026-05-29

CVE-2026-45661

A critical path traversal vulnerability in Dokploy v0.26.5 and earlier allows authenticated users to write arbitrary files to the filesystem during application deployment. When exploited in conjunction with Dokploy's remote server deployment feature, this vulnerability enables arbitrary file writes to remote server filesystems, automatic remote code execution via cron jobs, complete server compromise, dat [truncated]

CRITICAL Dokploy CVE published 2026-05-29

CVE-2026-45633

Dokploy versions 0.26.6 and earlier contain a critical command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges. This vulnerability has a CVSS 3.1 score of 9.9 (Critical). The issue was published on May 2 [truncated]

CRITICAL Dokploy CVE published 2026-05-29

CVE-2026-45632

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions 0.26.7 and earlier, the schedule router does not enforce organization or role-based access controls. This allows any authenticated user to create, update, run, or delete schedules belonging to other organizations if they know the scheduleId or serverId. Schedule types 'server' and 'dokploy-server' write and execute scripts on the h [truncated]

CRITICAL Dokploy CVE published 2026-05-29

CVE-2026-45631

CVE-2026-45631 is a critical authentication bypass vulnerability in Dokploy, a self-hostable Platform as a Service (PaaS), affecting versions 0.27.0 through 0.29.2. The vulnerability stems from a hardcoded fallback value for the BETTER_AUTH_SECRET configuration parameter (set to 'better-auth-secret-123456789'), which allows unauthenticated attackers to forge valid email verification JWTs. Successful explo [truncated]

CRITICAL Dokploy CVE published 2026-05-29

CVE-2026-45630

A critical OS command injection vulnerability in Dokploy, a self-hostable Platform-as-a-Service (PaaS) solution, allows authenticated admin or owner users to execute arbitrary system commands on remote servers. The vulnerability exists in the `application.updateTraefikConfig` tRPC endpoint in versions 0.28.8 and earlier, where unsanitized user input is interpolated into shell `echo` commands. This represe [truncated]

CRITICAL Dokploy CVE published 2026-05-29

CVE-2026-45629

**Executive Summary:** Dokploy versions 0.28.8 and earlier contain a critical authenticated OS command injection vulnerability in the `/listen-deployment` WebSocket endpoint. Any organization member can execute arbitrary system commands on remote servers managed by Dokploy, resulting in full server compromise. This vulnerability carries a CVSS 3.1 score of 9.9 (Critical).

CRITICAL Dokploy CVE published 2026-05-29

CVE-2026-45628

## Summary **CVE-2026-45628** is a **critical** (CVSS 9.6) command-injection vulnerability in Dokploy, a self-hosted Platform-as-a-Service (PaaS). Versions 0.29.2 and earlier construct shell commands using JavaScript template literals and execute them via `child_process.exec()` (which invokes `/bin/sh -c`). User-supplied inputs—specifically branch names, repository URLs, and Docker credentials—are interpo [truncated]

MEDIUM Dokploy CVE published 2026-05-29

CVE-2026-43917

CVE-2026-43917 documents an authorization bypass in Dokploy, a self-hostable Platform-as-a-Service (PaaS) solution. In versions 0.19.0 and earlier, the `protectedProcedure` middleware authenticates users but fails to enforce organization-level scoping. This allows authenticated users to access or manipulate resources across organizational boundaries without explicit permission checks at the middleware lay [truncated]

CRITICAL Dokploy CVE published 2026-05-29

CVE-2026-45663

A critical command injection vulnerability in Dokploy's Docker file upload functionality allows authenticated attackers to execute arbitrary OS commands on the host. The flaw exists in versions 0.29.1 and earlier, where the destinationPath parameter is unsafely interpolated into shell commands during docker cp operations. Attackers can inject shell metacharacters to escape the intended command context. Th [truncated]

HIGH Dokploy CVE published 2026-05-29

CVE-2026-45662

A command injection vulnerability exists in Dokploy versions 0.29.0 and earlier. The deleteRegistry function in packages/server/src/services/registry.ts executes docker logout ${response.registryUrl} without shell escaping, while the docker login command in the same file correctly uses shEscape(). This inconsistency allows authenticated attackers with registry deletion privileges to inject arbitrary shell [truncated]

CRITICAL Dokploy CVE published 2026-05-18

CVE-2026-27130

CVE-2026-27130 is a critical command injection flaw in Dokploy affecting versions 0.26.6 and below. User-controlled application names can pass through weak sanitization, bypass missing schema validation, and reach shell commands through direct interpolation. In practice, an authenticated attacker who controls appName during application creation may be able to trigger server-side command execution when ser [truncated]