PT-2026-69908 · Dokploy · Dokploy

CVE-2026-72867

·

Published

2026-08-10

·

Updated

2026-08-13

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dokploy versions 0.29.3 through 0.29.12
Description Insufficient server-side validation in the branch fields of packages/server/src/db/schema/compose.ts allows a direct compose.update request to store malicious values in customGitBranch, branch, gitlabBranch, bitbucketBranch, or giteaBranch. A low-privileged authenticated user can then trigger compose.deploy, which passes these stored values to shell-based Git clone commands within packages/server/src/utils/providers/git.ts, github.ts, gitlab.ts, bitbucket.ts, and gitea.ts, leading to arbitrary host command execution.
Recommendations Update to version 0.29.13.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72867
GHSA-CG8G-X23V-5FW8

Affected Products

Dokploy