Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-72868: Dokploy: Malicious data can execute commands as host root
CVE-2026-72868
CVE-2026-72868
Summary
Dokploy users are at risk of a security breach if an attacker gains access to a low-privileged organization member's account. This can happen if an attacker is able to manipulate certain settings in Dokploy. To protect yourself, make sure to update Dokploy to the latest version, which is 0.29.13 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dokploy | dokploy | < 0.29.13 |
Original title
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provid...
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection into an rclone ls command executed through child_process.exec. The `withPermission("destination", "create")` path permits a low-privileged organization member to reach the mutation, close a quoted argument with a crafted field, and execute arbitrary commands in the root Dokploy container, which has access to the host Docker socket. This issue is fixed in version 0.29.13.
mitre CVSS3.1
9.9
Vulnerability type
CWE-78
OS Command Injection
CWE-862
Missing Authorization
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-f6x8-vfwh-8hjr x_refsource_CONFIRM
- https://github.com/Dokploy/dokploy/pull/4873 x_refsource_MISC
- https://github.com/Dokploy/dokploy/commit/eeb6e7b8ea88e4b4b1fac8460755464100516a... x_refsource_MISC
- https://github.com/Dokploy/dokploy/releases/tag/v0.29.13 x_refsource_MISC
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026