OS Command Injection Vulnerability in Dokploy Platform by Dokploy
CVE-2026-45630

9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45630?

Dokploy, a self-hostable Platform as a Service (PaaS), has a vulnerability that allows authenticated admin or owner users to inject arbitrary system commands. This vulnerability arises from unsanitized input in the application.updateTraefikConfig tRPC endpoint, impacting versions 0.28.8 and earlier. Exploiting this flaw can lead to unauthorized access and control over remote servers, posing significant security risks to affected installations.

Affected Version(s)

dokploy <= 0.28.8

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.