Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-72879: Dokploy: Malicious Docker Commands Can Be Executed on Server
CVE-2026-72879
CVE-2026-72879
Summary
Dokploy's self-hosted Platform as a Service (PaaS) is affected. An attacker with access to a project can use malicious registry credentials to execute arbitrary commands on the server, potentially accessing other containers or sensitive data. Update to version 0.29.8 to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dokploy | dokploy | < 0.29.8 |
Original title
Dokploy: Command Injection via Registry Credentials in Swarm Upload
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and registry.registryUrl directly into a shell command without escaping. An authenticated user with project access can configure malicious registry credentials and trigger a swarm deployment to execute arbitrary OS commands on the Dokploy server, read or modify host files, and access other containers through Docker. This issue is fixed in version 0.29.8.
nvd CVSS4.0
9.4
Vulnerability type
CWE-78
OS Command Injection
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026