PT-2026-44937 · Dokploy · Dokploy

·

CVE-2026-45633

·

Published

2026-05-29

·

Updated

2026-07-22

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dokploy versions prior to 0.26.7
Description Dokploy is a self-hostable Platform as a Service (PaaS) that contains a command injection issue. Authenticated users can execute arbitrary commands with root privileges via the '/docker-container-logs' WebSocket endpoint. This occurs because the tail and since parameters are not validated and are directly concatenated into shell commands.
Recommendations Update to a version later than 0.26.6. Avoid using the tail and since parameters in the '/docker-container-logs' endpoint until the update is applied.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45633
GHSA-WMQJ-WR9Q-327P

Affected Products

Dokploy