CVE-2026-72862: OS Command Injection Vulnerability in Dokploy
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CVE-2026-72862 has been published, detailing a critical OS command injection vulnerability in Dokploy, a self-hostable PaaS. The flaw affects versions prior to 0.29.13, where user-controlled dockerImage fields are passed unquoted into shell commands. This vulnerability could allow attackers to execute arbitrary commands on the server. The CVSS base score assigned to this vulnerability is 9.9, indicating a high severity level. The vulnerability has been confirmed and is now patched in version 0.29.13. Users of Dokploy are urged to update their systems to mitigate potential exploitation. The vulnerability affects multiple database service deployment functions, including mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts. As of now, no active exploitation has been reported, but the potential for severe impact exists.
Key Points: • CVE-2026-72862 is a critical OS command injection vulnerability in Dokploy. • The vulnerability affects multiple database service deployment functions prior to version 0.29.13. • A CVSS base score of 9.9 indicates a high severity level, and users are urged to update immediately.