Command Injection Vulnerability in Dokploy Platform as a Service
CVE-2026-72877
9.6CRITICAL
What is CVE-2026-72877?
The Dokploy platform, which offers self-hostable PaaS solutions, is susceptible to a command injection vulnerability affecting versions prior to 0.29.13. In the method buildRemoteDocker(), the dockerImage field is processed without being properly quoted, allowing an authenticated user the capability to execute arbitrary shell commands. This exposure not only jeopardizes the integrity of the local build host but can also compromise remote SSH build targets, leading to unauthorized access to host secrets and other project data. Users are encouraged to update to version 0.29.13 or higher to mitigate this risk.
Affected Version(s)
dokploy < 0.29.13
