Command Injection Vulnerability in Dokploy Platform by Dokploy
CVE-2026-72738

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72738?

A command injection vulnerability exists in Dokploy, a self-hostable PaaS solution, allowing authenticated users with backup:read permission to execute arbitrary commands on the host system. This occurs due to improper handling of the search parameter in the backup.listBackupFiles endpoint, which is passed to an rclone command executed via child_process.exec(). The issue has been rectified in version 0.29.13, significantly improving the security posture of Dokploy.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.