Command Injection Vulnerability in Dokploy PaaS
CVE-2026-72884
8.7HIGH
What is CVE-2026-72884?
Dokploy, a self-hostable Platform as a Service (PaaS), has a command injection vulnerability due to insufficient sanitization of user input in its service update functionality. Before version 0.29.13, the method sanitizeCommand could allow an authenticated user with access to update a Compose service to inject shell metacharacters. This flaw enables the execution of arbitrary commands on the Dokploy host, posing a significant security risk. Users are advised to upgrade to version 0.29.13 or later to mitigate this vulnerability.
Affected Version(s)
dokploy < 0.29.13
