Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-72880: Dokploy: Unsecured File Writes and Unauthorized OS Commands

CVE-2026-72880 CVE-2026-72880
Summary

Dokploy's self-hosted Platform as a Service (PaaS) has a security issue that allows an authenticated user to write files outside the intended directory or run unauthorized system commands. This is fixed in version 0.29.13, so update Dokploy to this version to protect your system.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
dokploy dokploy < 0.29.13
Original title
Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath`
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a client-supplied certificatePath, and packages/server/src/services/certificate.ts joins that value to the certificate root without confinement. An authenticated user with certificate create or delete permission can use certificatePath to write attacker-controlled certificate content outside the intended directory or delete an out-of-root directory. This vulnerability is fixed in 0.29.13.
nvd CVSS3.1 9.9
Vulnerability type
CWE-78 OS Command Injection
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026