Path Traversal Vulnerability in Dokploy Affects Settings Component
CVE-2026-82954

9.4CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82954?

A concerning vulnerability has been identified in Dokploy version 0.29.7, specifically impacting the Settings component within the function writeTraefikConfigInPath. This flaw allows malicious actors to manipulate the 'path' argument, enabling them to execute path traversal attacks. Consequently, attackers can access directories and files outside the intended directory structure. Given that the exploit is now publicly available, it significantly raises the urgency for users to patch their installations. The vendor was informed of the issue prior to its disclosure but did not respond to address the concern.

Affected Version(s)

Dokploy 0.29.0

Dokploy 0.29.1

Dokploy 0.29.2

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Alves (VulDB User)
VulDB CNA Team
.