CVE-2026-45791
- EPSS 0.32%
- Veröffentlicht 17.08.2026 21:25:53
- Zuletzt bearbeitet 18.08.2026 16:17:09
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/user.ts updates account.password without deleting other rows from session, allowing a compromised bette...
- EPSS 0.28%
- Veröffentlicht 17.08.2026 21:24:22
- Zuletzt bearbeitet 18.08.2026 16:17:09
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account wit...
CVE-2026-72902
- EPSS 0.54%
- Veröffentlicht 10.08.2026 19:41:40
- Zuletzt bearbeitet 12.08.2026 23:17:22
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server because registry.testRegistry and registry.testRegistryById ...
CVE-2026-72901
- EPSS 0.63%
- Veröffentlicht 10.08.2026 19:40:15
- Zuletzt bearbeitet 13.08.2026 16:19:02
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create...
CVE-2026-72886
- EPSS 0.36%
- Veröffentlicht 10.08.2026 19:38:24
- Zuletzt bearbeitet 10.08.2026 20:17:35
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin ...
- EPSS 0.58%
- Veröffentlicht 10.08.2026 19:31:36
- Zuletzt bearbeitet 11.08.2026 15:17:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokploy/components/dashboard/application/build/show.tsx flows through getDockerContextPath in packages/server/src/utils/filesystem/dir...
CVE-2026-72884
- EPSS 0.43%
- Veröffentlicht 10.08.2026 19:30:07
- Zuletzt bearbeitet 11.08.2026 15:17:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts only trims whitespace and strips surrounding quotes from compose.command before exportEnvCommand and doc...
CVE-2026-72883
- EPSS 0.4%
- Veröffentlicht 10.08.2026 19:28:45
- Zuletzt bearbeitet 12.08.2026 23:17:22
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts, an...
CVE-2026-72882
- EPSS 0.36%
- Veröffentlicht 10.08.2026 19:27:09
- Zuletzt bearbeitet 13.08.2026 18:18:17
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for a service can inject shell metacharacters into filePath, causing Dokploy to execute attacker-controll...
CVE-2026-72881
- EPSS 0.47%
- Veröffentlicht 10.08.2026 19:21:05
- Zuletzt bearbeitet 10.08.2026 20:17:34
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts interpolate database names, use...