Command Injection Vulnerability in Dokploy Platform by Dokploy
CVE-2026-45633

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45633?

Dokploy, a self-hostable Platform as a Service (PaaS), has a command injection vulnerability found in the /docker-container-logs WebSocket endpoint. This flaw affects versions 0.26.6 and earlier, where user inputs for the tail and since parameters are inadequately validated. Consequently, authenticated users can manipulate these inputs to execute arbitrary shell commands with root privileges, posing significant security risks.

Affected Version(s)

dokploy <= 0.26.6

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.