PT-2026-44933 · Dokploy · Dokploy

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2026-45629

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compromise.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-45629

Affected Products

Dokploy