Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Dokploy — Vulnerabilities & Security Advisories 57

Browse all 57 CVE security advisories affecting Dokploy. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dokploy serves as a deployment automation platform for web applications, enabling developers to streamline containerized service deployments. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, often stemming from improper input validation and access control weaknesses. The platform's seven recorded CVEs highlight recurring patterns in insecure default configurations and insufficient sanitization of user-supplied data. While no major public security incidents have been widely documented, the consistent discovery of critical vulnerabilities suggests ongoing challenges in secure coding practices and configuration management within the platform's architecture.

Top products by Dokploy: dokploy
CVE ID Title CVSS Severity Published
CVE-2026-72862 Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72740 Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72739 Dokploy: Command Injection via Compose Shell Execution — dokploy CWE-78 6.5 Medium 2026-08-10
CVE-2026-72738 Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-72737 Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups — dokploy CWE-639 9.6 Critical 2026-08-10
CVE-2026-72736 Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE — dokploy CWE-77 9.9 Critical 2026-08-10
CVE-2026-72735 Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution — dokploy CWE-77 9.9 Critical 2026-08-10
CVE-2026-72734 Dokploy: Cross-organization authorization bypass in server.remove allows deletion of another organization's server registration — dokploy CWE-639 8.4 High 2026-08-10
CVE-2026-72733 Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore — dokploy CWE-78 9.9 Critical 2026-08-10
CVE-2026-45629 Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint — dokploy CWE-78 9.9 Critical 2026-05-29
CVE-2026-43917 Dokploy: Cross-Organization IDOR - Multiple tRPC endpoints missing activeOrganizationId validation — dokploy CWE-639 - - 2026-05-29
CVE-2026-45628 Dokploy: Command Injection via Unescaped Branch Fields in Deployment Pipeline — dokploy CWE-20 9.6 Critical 2026-05-29
CVE-2026-45630 Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement — dokploy CWE-78 9.0 Critical 2026-05-29
CVE-2026-45631 Dokploy: Pre-Auth Admin Takeover via Hardcoded Authentication Secret — dokploy CWE-798 10.0 Critical 2026-05-29
CVE-2026-45632 Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution — dokploy CWE-78 9.9 Critical 2026-05-29
CVE-2026-45633 Dokploy: Command Injection in /docker-container-logs Endpoint — dokploy CWE-78 9.9 Critical 2026-05-29
CVE-2026-45661 Dokploy: Remote Code Execution through Path Traversal — dokploy CWE-22 9.9 Critical 2026-05-29
CVE-2026-45662 Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion) — dokploy CWE-78 8.8 High 2026-05-29
CVE-2026-45663 Dokploy: Remote Code Execution via destinationPath in Container File Upload — dokploy CWE-77 9.9 Critical 2026-05-29
CVE-2026-27130 Dokploy has Command Injection in its Service Operations — dokploy CWE-78 9.9 Critical 2026-05-18
CVE-2026-24841 Dokploy Vulnerable to Authenticated Remote Code Execution via Command Injection in Docker Container Terminal WebSocket Endpoint — dokploy CWE-78 9.9 Critical 2026-01-28
CVE-2026-24840 Dokploy uses hardcoded credentials in installation script, which could result in database access — dokploy CWE-798 8.0 High 2026-01-28
CVE-2026-24839 Dokploy has a clickjacking vulnerability - Missing X-Frame-Options and CSP frame-ancestors headers — dokploy CWE-1021 4.7 Medium 2026-01-28
CVE-2025-53825 Dokploy's Preview Deployments are vulnerable to Remote Code Execution — dokploy CWE-862 9.4 Critical 2025-07-14
CVE-2025-53375 Dokploy allows attackers to read any file that the Traefik process user can access — dokploy CWE-22 8.8AI High AI 2025-07-07
CVE-2025-53376 Dokploy allows attackers to run arbitrary OS commands on the Dokploy host. — dokploy CWE-78 8.8AI High AI 2025-07-07
CVE-2025-53374 Dokploy Improperly Discloses User Information via user.one Endpoint — dokploy CWE-359 4.3AI Medium AI 2025-07-07

This page lists every published CVE security advisory associated with Dokploy. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.