๐Ÿ” CVE Alert

CVE-2026-72881

UNKNOWN 0.0

Dokploy: Command Injection via database credentials in backup/restore commands

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts interpolate database names, usernames, and passwords into nested shell command strings passed to child_process.exec(). An authenticated administrator with permission to create databases and configure backups can use crafted database configuration fields to execute arbitrary commands inside PostgreSQL, MariaDB, MySQL, MongoDB, or LibSQL containers, exposing database data and credentials and potentially enabling escape when a container is overprivileged. This issue is fixed in version 0.29.13.

CWE CWE-78
Vendor dokploy
Product dokploy
Published Aug 10, 2026
Last Updated Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for dokploy dokploy

Be the first to know when new unknown vulnerabilities affecting dokploy dokploy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Dokploy / dokploy
< 0.29.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Dokploy/dokploy/security/advisories/GHSA-qc73-mp78-4833 github.com: https://github.com/Dokploy/dokploy/pull/4862 github.com: https://github.com/Dokploy/dokploy/commit/ccd2e83c57d99f725220d37e0152270e0827d71b github.com: https://github.com/Dokploy/dokploy/releases/tag/v0.29.13