


Perceptive Security
SOC/SIEM Consultancy

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functio…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 17:11:09
Source:
nvd.nist.gov
Cloud & Virtualization, Web Technologies
A command injection vulnerability exists in Dokploy version 0.29.1 and earlier affecting the Docker file upload functionality. The vulnerability occurs when the destinationPath parameter is not properly sanitized and is directly interpolated into shell commands. Authenticated attackers can exploit this by including shell metacharacters like semicolons or quotes to escape the intended docker cp command. This allows execution of arbitrary OS commands on the Dokploy host system. The vulnerability affects the self-hostable Platform as a Service (PaaS) solution and requires authenticated access to exploit.
Technical details
Mitigation steps:
Affected products:
Dokploy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45663
https://github.com/Dokploy/dokploy/security/advisories/GHSA-9m66-74x3-5mwr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
