CVE-2026-72863
- EPSS 0.3%
- Veröffentlicht 10.08.2026 18:28:22
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateRequest() a...
CVE-2026-72862
- EPSS 0.43%
- Veröffentlicht 10.08.2026 18:18:53
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions pass user-controlled dockerImage fields unquoted i...
CVE-2026-72740
- EPSS 0.52%
- Veröffentlicht 10.08.2026 18:18:52
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interpolates its domain into the ssh-keyscan command from...
CVE-2026-72739
- EPSS 0.45%
- Veröffentlicht 10.08.2026 18:18:52
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and configuration into bash command strings. When a compose with a maliciou...
CVE-2026-72738
- EPSS 0.52%
- Veröffentlicht 10.08.2026 17:49:44
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter through normalizeS3Path and interpolates it into an rcl...
CVE-2026-72737
- EPSS 0.25%
- Veröffentlicht 10.08.2026 17:47:50
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId and use the ref...
CVE-2026-72736
- EPSS 0.43%
- Veröffentlicht 10.08.2026 17:40:44
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker Swarm cluste...
CVE-2026-72735
- EPSS 0.6%
- Veröffentlicht 10.08.2026 17:34:36
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik configuration with yaml.stringify and interpolates the re...
CVE-2026-72734
- EPSS 0.3%
- Veröffentlicht 10.08.2026 17:29:30
- Zuletzt bearbeitet 08.09.2026 20:54:37
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serverId and calls haveActiveServices, findServerById, ...
CVE-2026-72733
- EPSS 0.48%
- Veröffentlicht 10.08.2026 17:26:29
- Zuletzt bearbeitet 21.09.2026 19:17:09
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines from the user-controlled databaseName and backupFile fields without safely sep...