Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-72867: Dokploy: Malicious Branches Can Execute Arbitrary Commands

CVE-2026-72867 CVE-2026-72867
Summary

Dokploy users who haven't updated to version 0.29.13 are at risk of malicious branch names being used to execute arbitrary commands on their server. This could allow an attacker to take control of the server. We recommend updating to the latest version of Dokploy as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
dokploy dokploy >= 0.29.3, < 0.29.13
Original title
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without...
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.update request to store a malicious customGitBranch, branch, gitlabBranch, bitbucketBranch, or giteaBranch. A low-privileged authenticated user can trigger compose.deploy, which passes the stored branch to shell-based Git clone commands in packages/server/src/utils/providers/git.ts, github.ts, gitlab.ts, bitbucket.ts, and gitea.ts, resulting in arbitrary host command execution. This issue is fixed in version 0.29.13.
mitre CVSS3.1 9.9
Vulnerability type
CWE-20 Improper Input Validation
CWE-78 OS Command Injection
CWE-602
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026