CVE-2026-45629
- EPSS 0.76%
- Veröffentlicht 29.05.2026 16:40:59
- Zuletzt bearbeitet 02.06.2026 03:16:17
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote server...
CVE-2026-43917
- EPSS 0.23%
- Veröffentlicht 29.05.2026 16:40:05
- Zuletzt bearbeitet 29.05.2026 20:25:00
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware only verifies the user is authenticated - it does NOT enforce organization scoping. Each endpoint must individually verify the res...
CVE-2026-45628
- EPSS 0.23%
- Veröffentlicht 29.05.2026 16:33:23
- Zuletzt bearbeitet 29.05.2026 20:25:00
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (which runs through /bin/sh -c). User-supplied branc...
CVE-2026-45662
- EPSS 0.84%
- Veröffentlicht 29.05.2026 16:16:28
- Zuletzt bearbeitet 02.06.2026 03:16:17
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same...
CVE-2026-45663
- EPSS 0.87%
- Veröffentlicht 29.05.2026 16:16:28
- Zuletzt bearbeitet 29.05.2026 21:16:40
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath para...
- EPSS 0.76%
- Veröffentlicht 29.05.2026 16:15:36
- Zuletzt bearbeitet 01.06.2026 19:16:52
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote serv...
- EPSS 0.35%
- Veröffentlicht 29.05.2026 16:13:59
- Zuletzt bearbeitet 01.06.2026 17:17:10
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign-in...
CVE-2026-45632
- EPSS 0.26%
- Veröffentlicht 29.05.2026 16:11:19
- Zuletzt bearbeitet 02.06.2026 17:16:34
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to other o...
CVE-2026-45633
- EPSS 0.92%
- Veröffentlicht 29.05.2026 16:10:20
- Zuletzt bearbeitet 29.05.2026 20:25:00
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directl...
CVE-2026-45661
- EPSS 0.66%
- Veröffentlicht 29.05.2026 16:07:54
- Zuletzt bearbeitet 02.06.2026 03:16:17
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application depl...