Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-72872: Dokploy: Malicious Git Commands Executed on Host or Server
CVE-2026-72872
CVE-2026-72872
Summary
Dokploy's self-hosted Platform as a Service allows unauthorized users with deployment permissions to run arbitrary system commands on the host or target server. This is fixed in version 0.29.13. To protect yourself, update to the latest version of Dokploy.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dokploy | dokploy | < 0.29.13 |
Original title
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucke...
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers/bitbucket.ts interpolates those values into git clone commands executed through execAsync or execAsyncRemote, allowing a member with service deployment permission to execute arbitrary operating system commands on the Dokploy host or target server. This issue is fixed in version 0.29.13.
mitre CVSS3.1
9.9
Vulnerability type
CWE-78
OS Command Injection
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-grrj-6xrh-j6vp x_refsource_CONFIRM
- https://github.com/Dokploy/dokploy/pull/4855 x_refsource_MISC
- https://github.com/Dokploy/dokploy/commit/47347ab885b0ad1f5d0ef0e5e74bbba35c7f93... x_refsource_MISC
- https://github.com/Dokploy/dokploy/releases/tag/v0.29.13 x_refsource_MISC
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026