Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compromise.
References
Configurations
No configuration.
History
02 Jun 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Dokploy/dokploy/security/advisories/GHSA-r73h-qr3p-hf7f - |
29 May 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-29 18:17
Updated : 2026-06-02 03:16
NVD link : CVE-2026-45629
Mitre link : CVE-2026-45629
CVE.ORG link : CVE-2026-45629
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
