Directory Traversal Vulnerability in Dokploy Platform as a Service
CVE-2026-72880
9.9CRITICAL
What is CVE-2026-72880?
Dokploy, a self-hostable Platform as a Service (PaaS), has a directory traversal vulnerability due to improper handling of the client-supplied 'certificatePath' in its API. An authenticated user with permissions to create or delete certificates could exploit this flaw to write malicious certificate content outside the designated directory or to delete content from paths that should not be accessible. This issue was addressed in version 0.29.13, ensuring that user inputs are properly confined to prevent unauthorized access or modification of files.
Affected Version(s)
dokploy < 0.29.13
