Path Traversal Vulnerability in Dokploy Platform by Dokploy Inc.
CVE-2026-45661
9.9CRITICAL
What is CVE-2026-45661?
Dokploy, a self-hostable Platform as a Service, has a vulnerability in versions prior to 0.26.5 that allows authenticated users to exploit path traversal issues. This vulnerability permits unauthorized file writing to the filesystem during application deployment. When utilized with Dokploy's remote server deployment capability, it can lead to serious security risks such as remote code execution through scheduled cron jobs, total server compromise, and potential data exfiltration without user interaction, further compromising system integrity by allowing the installation of persistent backdoors. The flaw effectively undermines container isolation on remote deployments, representing a significant threat to system security.
Affected Version(s)
dokploy <= 0.26.5
