CVE-2026-45633

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.
Configurations

No configuration.

History

29 May 2026, 20:16

Type Values Removed Values Added
References () https://github.com/Dokploy/dokploy/security/advisories/GHSA-wmqj-wr9q-327p - () https://github.com/Dokploy/dokploy/security/advisories/GHSA-wmqj-wr9q-327p -

29 May 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 18:17

Updated : 2026-05-29 20:25


NVD link : CVE-2026-45633

Mitre link : CVE-2026-45633

CVE.ORG link : CVE-2026-45633


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')