Path Traversal Vulnerability in Dokploy Affects Settings Component
CVE-2026-82954
9.4CRITICAL
What is CVE-2026-82954?
A concerning vulnerability has been identified in Dokploy version 0.29.7, specifically impacting the Settings component within the function writeTraefikConfigInPath. This flaw allows malicious actors to manipulate the 'path' argument, enabling them to execute path traversal attacks. Consequently, attackers can access directories and files outside the intended directory structure. Given that the exploit is now publicly available, it significantly raises the urgency for users to patch their installations. The vendor was informed of the issue prior to its disclosure but did not respond to address the concern.
Affected Version(s)
Dokploy 0.29.0
Dokploy 0.29.1
Dokploy 0.29.2
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriel Alves (VulDB User)
VulDB CNA Team
