Remote Command Execution Vulnerability in Dokploy PaaS
CVE-2026-72735

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72735?

Dokploy, a self-hostable Platform as a Service, is susceptible to remote command execution due to improper handling of user-controlled Traefik configuration. Before version 0.29.13, the application serialized user input with yaml.stringify, allowing attackers to inject malicious commands through crafted inputs. This flaw can enable unauthorized execution of commands using the privileges of the configured SSH user on targeted remote servers. The vulnerability is linked to an incomplete fix of a prior issue and has been addressed in version 0.29.13.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.