top of page
perceptive_background_267k.jpg

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-containe…

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 19:07:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Web Technologies

Dokploy, a free self-hostable Platform as a Service (PaaS), contains a command injection vulnerability in versions 0.26.6 and earlier. The vulnerability exists in the /docker-container-logs WebSocket endpoint where the tail and since parameters are not properly validated. These unvalidated parameters are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges. This represents a critical security flaw that could lead to complete system compromise.

Technical details

Mitigation steps:

Affected products:

Dokploy

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page