Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-86059: Dokploy exposes Git credentials to unauthorized users
CVE-2026-86059 · published 17 days ago
Summary
In versions of Dokploy before 0.29.13, members of an organization could view plaintext Git provider credentials, such as OAuth tokens and private keys, through several API endpoints even if they did not have permission to use those providers. This allows them to access private repositories or change external workflows. Upgrade to version 0.29.13 or later to close the exposure.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dokploy | dokploy | < 0.29.13 |
Original advisory text
Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucket.one because those protected procedures return full provider rows without applying getAccessibleGitProviderIds or an organization check. The application.one route also returns nested GitHub, GitLab, Gitea, and Bitbucket relations from findApplicationById with GitHub App private keys, OAuth tokens, client secrets, webhook secrets, and app passwords even when hasGitProviderAccess is false. A member with application read access or a provider identifier can therefore bypass per-member provider assignment and use the exposed credentials to access private repositories or manipulate external workflows. This issue is fixed in version 0.29.13.
References
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-wx75-vxph-2m2f
- https://github.com/Dokploy/dokploy/pull/4859
- https://github.com/Dokploy/dokploy/commit/ecbaf6060bf6d00491ee51086e282589797772...
- https://github.com/Dokploy/dokploy/releases/tag/v0.29.13
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86059... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-86059 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-200Information Exposure
CWE-862Missing Authorization
Timeline
Published22 Sep 2026
Updated9 Oct 2026
First seen22 Sep 2026
Track software like this
Free during beta