VU#280377: Dokploy is vulnerable to OS command injection
Cybersecurity Classified by Officially
Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privileges and lead to full compromise of the target device.
Dokploy is an open-source Platform as a Service solution for deploying applications and databases on self-hosted servers. Dokploy allows authenticated users to create and schedule database backups and restore previously created backups. These backup operations are executed by the Dokploy process, which runs with root privileges by default.
Dokploy is vulnerable to OS command injection in its database backup creation and restoration functionality due to insufficient sanitization of user-controlled input before it is incorporated into shell commands. The vulnerable backup functionality constructs database-specific shell commands that directly interpolate a user-supplied database name, while the restore functionality incorporates a user-supplied backupFile value into a shell command. Both operations ultimately pass the resulting command to a shell execution helper that invokes /bin/bash as a child of the Dokploy process, without shell escaping or restrictions on shell metacharacters.
The affected parameters are exposed through tRPC procedures that only validate that the supplied values are non-empty strings. Consequently, authenticated users with permission to perform database backups can supply shell metacharacters that are interpreted by /bin/bash, resulting in arbitrary command execution on the Dokploy host with the root privileges of the Dokploy server process.
This is an extract. The publication continues at the source.
Read the original at the source: https://kb.cert.org/vuls/id/280377
Officially imported this from CERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
3 versions recorded. The original is kept in full — nothing is overwritten.
- v3 imported change on current
- v2 imported change on
- v1 as first published on
Provenance
- Organization
- CERT Coordination Center — imported from official source
- Official source
- https://www.kb.cert.org/vuls/atomfeed/ ATOM
- Imported
- September 17, 2026 15:30
- Versions
- 3 recorded
- Identity
-
https://kb.cert.org/vuls/id/280377