Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-72868: Dokploy: Malicious data can execute commands as host root

CVE-2026-72868 CVE-2026-72868
Summary

Dokploy users are at risk of a security breach if an attacker gains access to a low-privileged organization member's account. This can happen if an attacker is able to manipulate certain settings in Dokploy. To protect yourself, make sure to update Dokploy to the latest version, which is 0.29.13 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
dokploy dokploy < 0.29.13
Original title
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provid...
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection into an rclone ls command executed through child_process.exec. The `withPermission("destination", "create")` path permits a low-privileged organization member to reach the mutation, close a quoted argument with a crafted field, and execute arbitrary commands in the root Dokploy container, which has access to the host Docker socket. This issue is fixed in version 0.29.13.
mitre CVSS3.1 9.9
Vulnerability type
CWE-78 OS Command Injection
CWE-862 Missing Authorization
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026