Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

dokploy — Vulnerabilities & Security Advisories 56

All 56 CVE vulnerabilities found in dokploy, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities affecting Dokploy, an open-source deployment tool, categorized by weakness type and security tags. It collects records of security flaws discovered in the product, covering the historical time range from its initial release to the current version. Here you can track the vendor’s published security advisories, understand specific weakness classes such as authentication bypass or configuration errors, and look up the complete vulnerability history for this product. The entries link to official advisories, providing a centralized view of how security issues have evolved over time. This resource supports risk assessment by allowing users to identify recurring patterns in Dokploy’s vulnerability landscape without navigating fragmented external sources.

Vendor: Dokploy

CVE ID Title CVSS Severity Published
CVE-2026-82954 Dokploy Settings application.ts writeTraefikConfigInPath path traversal CWE-22 9.9 Critical 2026-08-31
CVE-2026-45791 Dokploy: Password Change Does Not Revoke Active Sessions CWE-613 5.9 Medium 2026-08-17
CVE-2026-45790 Dokploy: Invitation Role Escalation Allows Organization Takeover CWE-269 8.0 High 2026-08-17
CVE-2026-72902 Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById CWE-78 9.9 Critical 2026-08-10
CVE-2026-72901 Dokploy: Remote Code Execution via volume-backup CWE-78 9.9 Critical 2026-08-10
CVE-2026-72886 Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) CWE-269 9.9 Critical 2026-08-10
CVE-2026-72885 Dokploy: Authenticated Command Injection in Dokploy Dockerfile Builder CWE-78 - - 2026-08-10
CVE-2026-72884 Dokploy: Command Injection via Compose Custom Command CWE-78 8.7 High 2026-08-10
CVE-2026-72883 Dokploy: WebSocket Terminal Missing Service-Level Access Control CWE-862 8.8 High 2026-08-10
CVE-2026-72882 Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers CWE-78 9.9 Critical 2026-08-10
CVE-2026-72881 Dokploy: Command Injection via database credentials in backup/restore commands CWE-78 6.4 Medium 2026-08-10
CVE-2026-72880 Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` CWE-78 9.9 Critical 2026-08-10
CVE-2026-72879 Dokploy: Command Injection via Registry Credentials in Swarm Upload CWE-78 9.4 Critical 2026-08-10
CVE-2026-72878 Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments CWE-78 9.6 Critical 2026-08-10
CVE-2026-72877 Dokploy: Command Injection via dockerImage in buildRemoteDocker CWE-78 9.6 Critical 2026-08-10
CVE-2026-72876 Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* CWE-78 9.9 Critical 2026-08-10
CVE-2026-72875 Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile CWE-78 8.8 High 2026-08-10
CVE-2026-72874 Dokploy: Command Injection via Unescaped Git URL in Clone Commands CWE-78 8.7 High 2026-08-10
CVE-2026-72873 Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged service readers via `application.one` CWE-200 6.5 Medium 2026-08-10
CVE-2026-72872 Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` CWE-78 9.9 Critical 2026-08-10
CVE-2026-72871 Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback CWE-306 7.5 High 2026-08-10
CVE-2026-72870 Dokploy: Command Injection via Docker Credentials in buildRemoteDocker CWE-78 8.7 High 2026-08-10
CVE-2026-72869 Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE CWE-77 9.9 Critical 2026-08-10
CVE-2026-72868 Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection CWE-78 9.9 Critical 2026-08-10
CVE-2026-72867 Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) CWE-20 9.9 Critical 2026-08-10
CVE-2026-72866 WebSocket Terminal Auth Bypass CWE-862 8.8 High 2026-08-10
CVE-2026-72865 Dokploy: OS Command Injection via compose `composePath` CWE-78 9.9 Critical 2026-08-10
CVE-2026-72864 Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) CWE-862 9.9 Critical 2026-08-10
CVE-2026-72863 Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host CWE-269 9.9 Critical 2026-08-10
CVE-2026-72862 Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE CWE-78 9.9 Critical 2026-08-10

All 56 known CVE vulnerabilities affecting dokploy with full Chinese analysis, references, and POCs where available.