Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-72879: Dokploy: Malicious Docker Commands Can Be Executed on Server

CVE-2026-72879 CVE-2026-72879
Summary

Dokploy's self-hosted Platform as a Service (PaaS) is affected. An attacker with access to a project can use malicious registry credentials to execute arbitrary commands on the server, potentially accessing other containers or sensitive data. Update to version 0.29.8 to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
dokploy dokploy < 0.29.8
Original title
Dokploy: Command Injection via Registry Credentials in Swarm Upload
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and registry.registryUrl directly into a shell command without escaping. An authenticated user with project access can configure malicious registry credentials and trigger a swarm deployment to execute arbitrary OS commands on the Dokploy server, read or modify host files, and access other containers through Docker. This issue is fixed in version 0.29.8.
nvd CVSS4.0 9.4
Vulnerability type
CWE-78 OS Command Injection
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026