Command Injection Vulnerability in Dokploy PaaS Platform
CVE-2026-72878

9.6CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72878?

Dokploy, a free self-hostable Platform as a Service (PaaS), contains a vulnerability where the backup and restore pipeline constructs shell commands by directly interpolating user-controlled database fields into executable strings. This presents a significant risk as an authenticated admin or owner can inject arbitrary OS commands, leading to execution on the host machine running Dokploy. The vulnerability was addressed in version 0.29.13, and users are advised to upgrade to ensure system integrity.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.