Arbitrary Command Execution in Dokploy Platform Due to Improper Database Name Handling
CVE-2026-72869
9.9CRITICAL
What is CVE-2026-72869?
Dokploy, a self-hostable PaaS, was found to have a vulnerability where the backup.restoreBackupWithLogs tRPC subscription allows authenticated users to exploit the databaseName parameter. This parameter is passed to restore commands that are executed in the Docker-privileged host context with Node.js exec. An attacker with the appropriate permissions can craft a malicious database name, leading to the execution of arbitrary commands on the server. This issue has been addressed in version 0.29.13.
Affected Version(s)
dokploy < 0.29.13
