Remote Command Execution Vulnerability in Dokploy by Dokploy
CVE-2026-72902
9.9CRITICAL
What is CVE-2026-72902?
Dokploy, a free self-hostable Platform as a Service (PaaS), has a significant vulnerability that allows authenticated users to execute arbitrary commands on local or SSH-connected servers. This is due to the insecure interpolation of password fields in shell command executions within the application. The issue is remedied in version 0.29.13, which implements a safer command execution approach.
Affected Version(s)
dokploy < 0.29.13
