PT-2026-44934 · Dokploy · Dokploy

·

CVE-2026-45630

·

Published

2026-05-29

·

Updated

2026-07-22

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Dokploy versions prior to 0.28.9
Description Dokploy is a free, self-hostable Platform as a Service (PaaS). An OS command injection exists in the 'application.updateTraefikConfig' tRPC endpoint, which allows authenticated users with admin or owner privileges to execute arbitrary system commands on remote servers. This occurs due to unsanitized echo shell interpolation.
Recommendations Update to a version later than 0.28.8.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45630
GHSA-P787-6GQG-CVP5

Affected Products

Dokploy