Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

dokploy — Vulnerabilities & Security Advisories 56

All 56 CVE vulnerabilities found in dokploy, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities affecting Dokploy, an open-source deployment tool, categorized by weakness type and security tags. It collects records of security flaws discovered in the product, covering the historical time range from its initial release to the current version. Here you can track the vendor’s published security advisories, understand specific weakness classes such as authentication bypass or configuration errors, and look up the complete vulnerability history for this product. The entries link to official advisories, providing a centralized view of how security issues have evolved over time. This resource supports risk assessment by allowing users to identify recurring patterns in Dokploy’s vulnerability landscape without navigating fragmented external sources.

Vendor: Dokploy

CVE ID Title CVSS Severity Published
CVE-2026-72740 Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` CWE-78 9.9 Critical 2026-08-10
CVE-2026-72739 Dokploy: Command Injection via Compose Shell Execution CWE-78 6.5 Medium 2026-08-10
CVE-2026-72738 Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter CWE-78 9.9 Critical 2026-08-10
CVE-2026-72737 Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups CWE-639 9.6 Critical 2026-08-10
CVE-2026-72736 Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE CWE-77 9.9 Critical 2026-08-10
CVE-2026-72735 Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution CWE-77 9.9 Critical 2026-08-10
CVE-2026-72734 Dokploy: Cross-organization authorization bypass in server.remove allows deletion of another organization's server registration CWE-639 8.4 High 2026-08-10
CVE-2026-72733 Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore CWE-78 9.9 Critical 2026-08-10
CVE-2026-45629 Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint CWE-78 9.9 Critical 2026-05-29
CVE-2026-43917 Dokploy: Cross-Organization IDOR - Multiple tRPC endpoints missing activeOrganizationId validation CWE-639 - - 2026-05-29
CVE-2026-45628 Dokploy: Command Injection via Unescaped Branch Fields in Deployment Pipeline CWE-20 9.6 Critical 2026-05-29
CVE-2026-45630 Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement CWE-78 9.0 Critical 2026-05-29
CVE-2026-45631 Dokploy: Pre-Auth Admin Takeover via Hardcoded Authentication Secret CWE-798 10.0 Critical 2026-05-29
CVE-2026-45632 Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution CWE-78 9.9 Critical 2026-05-29
CVE-2026-45633 Dokploy: Command Injection in /docker-container-logs Endpoint CWE-78 9.9 Critical 2026-05-29
CVE-2026-45661 Dokploy: Remote Code Execution through Path Traversal CWE-22 9.9 Critical 2026-05-29
CVE-2026-45662 Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion) CWE-78 8.8 High 2026-05-29
CVE-2026-45663 Dokploy: Remote Code Execution via destinationPath in Container File Upload CWE-77 9.9 Critical 2026-05-29
CVE-2026-27130 Dokploy has Command Injection in its Service Operations CWE-78 9.9 Critical 2026-05-18
CVE-2026-24841 Dokploy Vulnerable to Authenticated Remote Code Execution via Command Injection in Docker Container Terminal WebSocket Endpoint CWE-78 9.9 Critical 2026-01-28
CVE-2026-24840 Dokploy uses hardcoded credentials in installation script, which could result in database access CWE-798 8.0 High 2026-01-28
CVE-2026-24839 Dokploy has a clickjacking vulnerability - Missing X-Frame-Options and CSP frame-ancestors headers CWE-1021 4.7 Medium 2026-01-28
CVE-2025-53825 Dokploy's Preview Deployments are vulnerable to Remote Code Execution CWE-862 9.4 Critical 2025-07-14
CVE-2025-53375 Dokploy allows attackers to read any file that the Traefik process user can access CWE-22 8.8AI High AI 2025-07-07
CVE-2025-53376 Dokploy allows attackers to run arbitrary OS commands on the Dokploy host. CWE-78 8.8AI High AI 2025-07-07
CVE-2025-53374 Dokploy Improperly Discloses User Information via user.one Endpoint CWE-359 4.3AI Medium AI 2025-07-07

All 56 known CVE vulnerabilities affecting dokploy with full Chinese analysis, references, and POCs where available.