Command Injection Vulnerability in Dokploy PaaS
CVE-2026-72740

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72740?

Dokploy, an open-source Platform as a Service (PaaS), is susceptible to a command injection vulnerability due to improper sanitization of user-controlled input. Specifically, the vulnerable code exists in the git.ts file, which allows an authenticated user with deployment permissions to manipulate the ssh-keyscan command by injecting arbitrary commands. This flaw can lead to potential exploitation, allowing unauthorized command execution on the Dokploy host during application deployments. The issue has been rectified in version 0.29.13, emphasizing the importance of keeping the software up to date.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.