Command Injection Vulnerability in Dokploy Platform as a Service
CVE-2026-72877

9.6CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72877?

The Dokploy platform, which offers self-hostable PaaS solutions, is susceptible to a command injection vulnerability affecting versions prior to 0.29.13. In the method buildRemoteDocker(), the dockerImage field is processed without being properly quoted, allowing an authenticated user the capability to execute arbitrary shell commands. This exposure not only jeopardizes the integrity of the local build host but can also compromise remote SSH build targets, leading to unauthorized access to host secrets and other project data. Users are encouraged to update to version 0.29.13 or higher to mitigate this risk.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.