Command Injection Vulnerability in Dokploy PaaS
CVE-2026-72740
9.9CRITICAL
What is CVE-2026-72740?
Dokploy, an open-source Platform as a Service (PaaS), is susceptible to a command injection vulnerability due to improper sanitization of user-controlled input. Specifically, the vulnerable code exists in the git.ts file, which allows an authenticated user with deployment permissions to manipulate the ssh-keyscan command by injecting arbitrary commands. This flaw can lead to potential exploitation, allowing unauthorized command execution on the Dokploy host during application deployments. The issue has been rectified in version 0.29.13, emphasizing the importance of keeping the software up to date.
Affected Version(s)
dokploy < 0.29.13
