Arbitrary Command Execution Vulnerability in Dokploy PaaS
CVE-2026-72875
8.8HIGH
What is CVE-2026-72875?
A vulnerability in Dokploy, a self-hostable Platform as a Service (PaaS), allows users with 'traefikFiles.read' permission to execute arbitrary commands on a managed server. This occurs because the setting 'settings.readTraefikFile' in the application improperly handles paths, enabling the interpolation of user-controlled input into a command execution context. The vulnerability has been resolved in version 0.29.13, and users are urged to update to secure their deployments.
Affected Version(s)
dokploy < 0.29.13
