๐Ÿ” CVE Alert

CVE-2026-72869

CRITICAL 9.9

Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL, MariaDB, MySQL, and MongoDB commands embed the value in nested shell text executed by Node.js exec. An authenticated user with backup:restore permission can supply a crafted databaseName that the host /bin/sh expands before docker exec, resulting in arbitrary commands running in the Docker-privileged host context. This issue is fixed in version 0.29.13.

CWE CWE-77 CWE-78
Vendor dokploy
Product dokploy
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for dokploy dokploy

Be the first to know when new critical vulnerabilities affecting dokploy dokploy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Dokploy / dokploy
< 0.29.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Dokploy/dokploy/security/advisories/GHSA-f7mp-9jfp-mjrr github.com: https://github.com/Dokploy/dokploy/pull/4862 github.com: https://github.com/Dokploy/dokploy/commit/ccd2e83c57d99f725220d37e0152270e0827d71b github.com: https://github.com/Dokploy/dokploy/releases/tag/v0.29.13