CVE-2026-72862: OS Command Injection Vulnerability in Dokploy

CVE-2026-72862: OS Command Injection Vulnerability in Dokploy

First seen 11 Aug 2026, 08:07 UTC Feedlynvd.nist.goveuvd.enisa.europa.euvulners.comvuldb.com 93% similarity 72.0

Article Content

Browse articles
ThreatCluster

CVE-2026-72862 has been published, detailing a critical OS command injection vulnerability in Dokploy, a self-hostable PaaS. The flaw affects versions prior to 0.29.13, where user-controlled dockerImage fields are passed unquoted into shell commands. This vulnerability could allow attackers to execute arbitrary commands on the server. The CVSS base score assigned to this vulnerability is 9.9, indicating a high severity level. The vulnerability has been confirmed and is now patched in version 0.29.13. Users of Dokploy are urged to update their systems to mitigate potential exploitation. The vulnerability affects multiple database service deployment functions, including mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts. As of now, no active exploitation has been reported, but the potential for severe impact exists.

Key Points: • CVE-2026-72862 is a critical OS command injection vulnerability in Dokploy. • The vulnerability affects multiple database service deployment functions prior to version 0.29.13. • A CVSS base score of 9.9 indicates a high severity level, and users are urged to update immediately.

ThreatCluster AI How this analysis works

Timeline

2026-08-10
CVE-2026-72862 published
NVD published details of a critical OS command injection vulnerability in Dokploy affecting versions before 0.29.13.
nvd.nist.gov
2026-08-11
Vulnerability patched
Dokploy released version 0.29.13, which fixes the OS command injection vulnerability.
Feedly

Community

Browse all →

Tracked Entities in This Story