Unauthenticated GitHub Integration Vulnerability in Dokploy by Dokploy
CVE-2026-72871

7.5HIGH

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72871?

Dokploy is a PaaS that had a security flaw allowing an unauthenticated API endpoint to trust potentially malicious inputs. This vulnerability could enable attackers to improperly configure GitHub App providers, compromising sensitive client secrets and webhook credentials. Versions prior to 0.29.13 are affected, and users are urged to update to the latest release to ensure their systems are secure.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.