CVE-2026-72883
- EPSS 0.4%
- Veröffentlicht 10.08.2026 19:28:45
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts, an...
CVE-2026-72882
- EPSS 0.36%
- Veröffentlicht 10.08.2026 19:27:09
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for a service can inject shell metacharacters into filePath, causing Dokploy to execute attacker-controll...
CVE-2026-72881
- EPSS 0.47%
- Veröffentlicht 10.08.2026 19:21:05
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts interpolate database names, use...
CVE-2026-72880
- EPSS 0.3%
- Veröffentlicht 10.08.2026 19:19:39
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a client-supplied certificatePath, and packages/server/src/services/certificate.t...
CVE-2026-72879
- EPSS 0.28%
- Veröffentlicht 10.08.2026 19:14:52
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and registry.registryUrl directly into a shell command wi...
CVE-2026-72878
- EPSS 0.27%
- Veröffentlicht 10.08.2026 19:11:39
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by directly interpolating user-controlled database fields into bash -c "..." and sh -c "..." strings, the...
CVE-2026-72877
- EPSS 0.4%
- Veröffentlicht 10.08.2026 19:02:28
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src/utils/providers/docker.ts and is validated only a...
CVE-2026-72876
- EPSS 0.47%
- Veröffentlicht 10.08.2026 19:00:54
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an...
CVE-2026-72875
- EPSS 0.54%
- Veröffentlicht 10.08.2026 18:59:33
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokploy/server/api/routers/settings.ts passes a path accepted by apiReadTraefikConfig to readConfigInPath in packages/server/src/utils/t...
CVE-2026-72874
- EPSS 0.35%
- Veröffentlicht 10.08.2026 18:57:40
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/src/utils/providers/git.ts interpolates customGitUrl and customGitBranch into a git clone command passed to execAsync or execAsyncR...