VU#280377: Dokploy is vulnerable to OS command injection

CERT Coordination Center Version 3 imported change current

Imported from official source

Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privileges and lead to full compromise of the target device. …

This version

Version
3 of 3
Recorded
September 24, 2026 20:00
Change
Imported change
Content hash
e93eb13c16a2727a8ff9c0127b4da82b
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.