Remote Command Execution Vulnerability in Dokploy PaaS
CVE-2026-72735
9.9CRITICAL
What is CVE-2026-72735?
Dokploy, a self-hostable Platform as a Service, is susceptible to remote command execution due to improper handling of user-controlled Traefik configuration. Before version 0.29.13, the application serialized user input with yaml.stringify, allowing attackers to inject malicious commands through crafted inputs. This flaw can enable unauthorized execution of commands using the privileges of the configured SSH user on targeted remote servers. The vulnerability is linked to an incomplete fix of a prior issue and has been addressed in version 0.29.13.
Affected Version(s)
dokploy < 0.29.13
