Path Traversal Vulnerability in Dokploy Platform by Dokploy Inc.
CVE-2026-45661

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45661?

Dokploy, a self-hostable Platform as a Service, has a vulnerability in versions prior to 0.26.5 that allows authenticated users to exploit path traversal issues. This vulnerability permits unauthorized file writing to the filesystem during application deployment. When utilized with Dokploy's remote server deployment capability, it can lead to serious security risks such as remote code execution through scheduled cron jobs, total server compromise, and potential data exfiltration without user interaction, further compromising system integrity by allowing the installation of persistent backdoors. The flaw effectively undermines container isolation on remote deployments, representing a significant threat to system security.

Affected Version(s)

dokploy <= 0.26.5

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.