Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Dokploy — Vulnerabilities & Security Advisories 57

Browse all 57 CVE security advisories affecting Dokploy. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dokploy serves as a deployment automation platform for web applications, enabling developers to streamline containerized service deployments. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, often stemming from improper input validation and access control weaknesses. The platform's seven recorded CVEs highlight recurring patterns in insecure default configurations and insufficient sanitization of user-supplied data. While no major public security incidents have been widely documented, the consistent discovery of critical vulnerabilities suggests ongoing challenges in secure coding practices and configuration management within the platform's architecture.

Top products by Dokploy: dokploy
CVE ID Title CVSS Severity Published
CVE-2026-93425 Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root — dokploy CWE-78 9.9 Critical 2026-09-24
CVE-2026-86059 Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one — dokploy CWE-200 9.6 Critical 2026-09-22
CVE-2026-45791 Dokploy: Password Change Does Not Revoke Active Sessions — dokploy CWE-613 5.9 Medium 2026-08-17
CVE-2026-45790 Dokploy: Invitation Role Escalation Allows Organization Takeover — dokploy CWE-269 8.0 High 2026-08-17
CVE-2026-72902 Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72901 Dokploy: Remote Code Execution via volume-backup — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72886 Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) — dokploy CWE-269 9.9 Critical 2026-08-10
CVE-2026-72885 Dokploy: Authenticated Command Injection in Dokploy Dockerfile Builder — dokploy CWE-78 - - 2026-08-10
CVE-2026-72884 Dokploy: Command Injection via Compose Custom Command — dokploy CWE-78 8.7 High 2026-08-10
CVE-2026-72883 Dokploy: WebSocket Terminal Missing Service-Level Access Control — dokploy CWE-862 8.8 High 2026-08-10
CVE-2026-72882 Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72881 Dokploy: Command Injection via database credentials in backup/restore commands — dokploy CWE-78 6.4 Medium 2026-08-10
CVE-2026-72880 Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72879 Dokploy: Command Injection via Registry Credentials in Swarm Upload — dokploy CWE-78 9.4 Critical 2026-08-10
CVE-2026-72878 Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments — dokploy CWE-78 9.6 Critical 2026-08-10
CVE-2026-72877 Dokploy: Command Injection via dockerImage in buildRemoteDocker — dokploy CWE-78 9.6 Critical 2026-08-10
CVE-2026-72876 Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72875 Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile — dokploy CWE-78 8.8 High 2026-08-10
CVE-2026-72874 Dokploy: Command Injection via Unescaped Git URL in Clone Commands — dokploy CWE-78 8.7 High 2026-08-10
CVE-2026-72873 Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged service readers via `application.one` — dokploy CWE-200 6.5 Medium 2026-08-10
CVE-2026-72872 Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72871 Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback — dokploy CWE-306 7.5 High 2026-08-10
CVE-2026-72870 Dokploy: Command Injection via Docker Credentials in buildRemoteDocker — dokploy CWE-78 8.7 High 2026-08-10
CVE-2026-72869 Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE — dokploy CWE-77 9.9 Critical 2026-08-10
CVE-2026-72868 Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72867 Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) — dokploy CWE-20 9.9 Critical 2026-08-10
CVE-2026-72866 WebSocket Terminal Auth Bypass — dokploy CWE-862 8.8 High 2026-08-10
CVE-2026-72865 Dokploy: OS Command Injection via compose `composePath` — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72864 Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) — dokploy CWE-862 9.9 Critical 2026-08-10
CVE-2026-72863 Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host — dokploy CWE-269 9.9 Critical 2026-08-10

This page lists every published CVE security advisory associated with Dokploy. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.