OS Command Injection Vulnerability in Dokploy - A PaaS Solution
CVE-2026-45629

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45629?

Dokploy, a self-hostable Platform as a Service (PaaS) solution, has a critical OS command injection vulnerability in its /listen-deployment WebSocket endpoint. This issue affects versions 0.28.8 and earlier, allowing authenticated users to execute arbitrary system commands on remote servers that are managed by Dokploy. If exploited, this vulnerability can lead to full server compromise, posing a significant threat to the security and integrity of hosted applications.

Affected Version(s)

dokploy <= 0.28.8

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.