CVE-2026-93425
- EPSS 0.62%
- Veröffentlicht 24.09.2026 15:45:46
- Zuletzt bearbeitet 24.09.2026 18:19:07
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/ser...
CVE-2026-86059
- EPSS 0.49%
- Veröffentlicht 22.09.2026 16:11:56
- Zuletzt bearbeitet 22.09.2026 18:17:24
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucket.one because...
CVE-2026-82954
- EPSS 0.62%
- Veröffentlicht 31.08.2026 21:45:06
- Zuletzt bearbeitet 02.09.2026 18:21:28
A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in pa...
CVE-2026-45791
- EPSS 0.32%
- Veröffentlicht 17.08.2026 21:25:53
- Zuletzt bearbeitet 08.09.2026 21:03:08
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/user.ts updates account.password without deleting other rows from session, allowing a compromised bette...
- EPSS 0.28%
- Veröffentlicht 17.08.2026 21:24:22
- Zuletzt bearbeitet 08.09.2026 21:03:08
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account wit...
CVE-2026-72902
- EPSS 0.54%
- Veröffentlicht 10.08.2026 19:41:40
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server because registry.testRegistry and registry.testRegistryById ...
CVE-2026-72901
- EPSS 0.63%
- Veröffentlicht 10.08.2026 19:40:15
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create...
CVE-2026-72886
- EPSS 0.36%
- Veröffentlicht 10.08.2026 19:38:24
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin ...
- EPSS 0.58%
- Veröffentlicht 10.08.2026 19:31:36
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokploy/components/dashboard/application/build/show.tsx flows through getDockerContextPath in packages/server/src/utils/filesystem/dir...
CVE-2026-72884
- EPSS 0.43%
- Veröffentlicht 10.08.2026 19:30:07
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts only trims whitespace and strips surrounding quotes from compose.command before exportEnvCommand and doc...