


Perceptive Security
SOC/SIEM Consultancy

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and e…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 19:07:03
Source:
nvd.nist.gov
Cloud & Virtualization, Web Technologies
CVE-2026-45628 affects Dokploy, a self-hostable Platform as a Service (PaaS), in versions 0.29.2 and earlier. The vulnerability involves command injection through JavaScript template literals where user-supplied branch names, repository URLs, and Docker credentials are interpolated directly into shell commands without proper escaping. Commands are executed via child_process.exec() through /bin/sh -c. Exploitation requires an authenticated user with application create/edit privileges. This represents a critical security flaw in the platform's command construction mechanism.
Technical details
Mitigation steps:
Affected products:
Dokploy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45628
https://github.com/Dokploy/dokploy/security/advisories/GHSA-3frc-cfh9-ch2c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
