CVE-2026-72880
- EPSS 0.3%
- Veröffentlicht 10.08.2026 19:19:39
- Zuletzt bearbeitet 11.08.2026 15:17:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a client-supplied certificatePath, and packages/server/src/services/certificate.t...
CVE-2026-72879
- EPSS 0.28%
- Veröffentlicht 10.08.2026 19:14:52
- Zuletzt bearbeitet 11.08.2026 15:17:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and registry.registryUrl directly into a shell command wi...
CVE-2026-72878
- EPSS 0.27%
- Veröffentlicht 10.08.2026 19:11:39
- Zuletzt bearbeitet 12.08.2026 23:17:22
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by directly interpolating user-controlled database fields into bash -c "..." and sh -c "..." strings, the...
CVE-2026-72877
- EPSS 0.4%
- Veröffentlicht 10.08.2026 19:02:28
- Zuletzt bearbeitet 13.08.2026 16:19:02
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src/utils/providers/docker.ts and is validated only a...
CVE-2026-72876
- EPSS 0.47%
- Veröffentlicht 10.08.2026 19:00:54
- Zuletzt bearbeitet 10.08.2026 20:17:33
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an...
CVE-2026-72875
- EPSS 0.54%
- Veröffentlicht 10.08.2026 18:59:33
- Zuletzt bearbeitet 11.08.2026 15:17:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokploy/server/api/routers/settings.ts passes a path accepted by apiReadTraefikConfig to readConfigInPath in packages/server/src/utils/t...
CVE-2026-72874
- EPSS 0.35%
- Veröffentlicht 10.08.2026 18:57:40
- Zuletzt bearbeitet 11.08.2026 15:17:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/src/utils/providers/git.ts interpolates customGitUrl and customGitBranch into a git clone command passed to execAsync or execAsyncR...
CVE-2026-72873
- EPSS 0.33%
- Veröffentlicht 10.08.2026 18:56:14
- Zuletzt bearbeitet 12.08.2026 23:17:22
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts returns provider relations loaded by findApplicationById in packages/server/src/services/application.ts...
CVE-2026-72872
- EPSS 0.37%
- Veröffentlicht 10.08.2026 18:50:23
- Zuletzt bearbeitet 13.08.2026 18:18:17
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers/bi...
CVE-2026-72871
- EPSS 0.29%
- Veröffentlicht 10.08.2026 18:47:58
- Zuletzt bearbeitet 10.08.2026 20:17:33
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the state ...