top of page
perceptive_background_267k.jpg

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functio…

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 17:11:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Web Technologies

A command injection vulnerability exists in Dokploy version 0.29.1 and earlier affecting the Docker file upload functionality. The vulnerability occurs when the destinationPath parameter is not properly sanitized and is directly interpolated into shell commands. Authenticated attackers can exploit this by including shell metacharacters like semicolons or quotes to escape the intended docker cp command. This allows execution of arbitrary OS commands on the Dokploy host system. The vulnerability affects the self-hostable Platform as a Service (PaaS) solution and requires authenticated access to exploit.

Technical details

Mitigation steps:

Affected products:

Dokploy

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page