Command Injection Vulnerability in Dokploy Platform by Dokploy
CVE-2026-72738
9.9CRITICAL
What is CVE-2026-72738?
A command injection vulnerability exists in Dokploy, a self-hostable PaaS solution, allowing authenticated users with backup:read permission to execute arbitrary commands on the host system. This occurs due to improper handling of the search parameter in the backup.listBackupFiles endpoint, which is passed to an rclone command executed via child_process.exec(). The issue has been rectified in version 0.29.13, significantly improving the security posture of Dokploy.
Affected Version(s)
dokploy < 0.29.13
