Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-72867: Dokploy: Malicious Branches Can Execute Arbitrary Commands
CVE-2026-72867
CVE-2026-72867
Summary
Dokploy users who haven't updated to version 0.29.13 are at risk of malicious branch names being used to execute arbitrary commands on their server. This could allow an attacker to take control of the server. We recommend updating to the latest version of Dokploy as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dokploy | dokploy | >= 0.29.3, < 0.29.13 |
Original title
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without...
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.update request to store a malicious customGitBranch, branch, gitlabBranch, bitbucketBranch, or giteaBranch. A low-privileged authenticated user can trigger compose.deploy, which passes the stored branch to shell-based Git clone commands in packages/server/src/utils/providers/git.ts, github.ts, gitlab.ts, bitbucket.ts, and gitea.ts, resulting in arbitrary host command execution. This issue is fixed in version 0.29.13.
mitre CVSS3.1
9.9
Vulnerability type
CWE-20
Improper Input Validation
CWE-78
OS Command Injection
CWE-602
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-cg8g-x23v-5fw8 x_refsource_CONFIRM
- https://github.com/Dokploy/dokploy/pull/4855 x_refsource_MISC
- https://github.com/Dokploy/dokploy/commit/47347ab885b0ad1f5d0ef0e5e74bbba35c7f93... x_refsource_MISC
- https://github.com/Dokploy/dokploy/releases/tag/v0.29.13 x_refsource_MISC
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026