Dokploy

Dokploy

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Veröffentlicht 29.05.2026 16:16:28
  • Zuletzt bearbeitet 21.07.2026 15:10:00

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same...

  • EPSS 0.87%
  • Veröffentlicht 29.05.2026 16:16:28
  • Zuletzt bearbeitet 21.07.2026 15:10:00

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath para...

  • EPSS 0.76%
  • Veröffentlicht 29.05.2026 16:15:36
  • Zuletzt bearbeitet 22.07.2026 06:10:00

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote serv...

  • EPSS 0.35%
  • Veröffentlicht 29.05.2026 16:13:59
  • Zuletzt bearbeitet 22.07.2026 06:10:00

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign-in...

  • EPSS 0.26%
  • Veröffentlicht 29.05.2026 16:11:19
  • Zuletzt bearbeitet 22.07.2026 06:10:00

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to other o...

  • EPSS 0.92%
  • Veröffentlicht 29.05.2026 16:10:20
  • Zuletzt bearbeitet 22.07.2026 06:10:00

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directl...

  • EPSS 0.66%
  • Veröffentlicht 29.05.2026 16:07:54
  • Zuletzt bearbeitet 22.07.2026 06:10:00

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application depl...

  • EPSS 0.99%
  • Veröffentlicht 18.05.2026 21:16:39
  • Zuletzt bearbeitet 24.07.2026 13:10:00

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input sanitization, lack of schema validation and direct...

Exploit
  • EPSS 2.52%
  • Veröffentlicht 28.01.2026 00:18:23
  • Zuletzt bearbeitet 04.02.2026 17:37:04

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokploy's WebSocket endpoint `/docker-container-terminal`. The `containerId` and `activeWay` parameters a...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 28.01.2026 00:15:57
  • Zuletzt bearbeitet 04.02.2026 17:55:14

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the d...