CVE-2026-72875

8.8

Dokploy · dokploy

Dokploy versions prior to 0.29.13 are vulnerable to OS command injection, which can be exploited by an authenticated user to achieve arbitrary command execution.

Executive summary

An OS command injection vulnerability in Dokploy permits authenticated users to execute arbitrary commands, posing a high risk to the security and availability of the PaaS environment.

Vulnerability

This vulnerability occurs due to improper neutralization of special elements within OS commands. It allows an authenticated user to inject malicious instructions that are then executed by the underlying operating system.

Business impact

Exploitation of this flaw allows an attacker to bypass security boundaries, potentially leading to unauthorized access to the underlying infrastructure hosting the Platform as a Service. With a CVSS score of 8.8, this represents an extreme risk to the integrity of all applications managed by the affected Dokploy instance.

Remediation

Immediate Action: Upgrade Dokploy to version 0.29.13 or later to apply the necessary security fixes.

Proactive Monitoring: Monitor server logs for unexpected command execution and analyze application performance for signs of unauthorized resource consumption or anomalous activity.

Compensating Controls: Implement network-level segmentation to isolate the Dokploy management plane and utilize a Web Application Firewall to sanitize incoming requests for command injection characters.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The ability for an authenticated user to perform command injection is a significant security failure that must be addressed immediately. All administrators should verify their current deployment version and perform the update to 0.29.13 as soon as possible to mitigate the risk of unauthorized system control.

More Dokploy CVEs