PT-2026-69880 · Dokploy · Dokploy

CVE-2026-72735

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dokploy versions prior to 0.29.13
Description In the writeTraefikConfigRemote function within packages/server/src/utils/traefik/application.ts, user-controlled Traefik configuration is serialized using yaml.stringify and then interpolated into an echo command executed via execAsyncRemote. An attacker can use single quotes in basic authentication usernames, domain host values, middleware configuration, or redirect regex and replacement fields to terminate shell quoting. This allows the execution of arbitrary commands on managed remote servers with the privileges of the configured SSH user.
Recommendations Update to version 0.29.13.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72735
GHSA-478P-CX3J-HGHC

Affected Products

Dokploy