Command Injection Vulnerability in Dokploy PaaS Platform
CVE-2026-72878
9.6CRITICAL
What is CVE-2026-72878?
Dokploy, a free self-hostable Platform as a Service (PaaS), contains a vulnerability where the backup and restore pipeline constructs shell commands by directly interpolating user-controlled database fields into executable strings. This presents a significant risk as an authenticated admin or owner can inject arbitrary OS commands, leading to execution on the host machine running Dokploy. The vulnerability was addressed in version 0.29.13, and users are advised to upgrade to ensure system integrity.
Affected Version(s)
dokploy < 0.29.13
