NONE · 0

CVE-2026-72879

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and reg...

Vulnerability Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and registry.registryUrl directly into a shell command without escaping. An authenticated user with project access can configure malicious registry credentials and trigger a swarm deployment to execute arbitrary OS commands on the Dokploy server, read or modify host files, and access other containers through Docker. This issue is fixed in version 0.29.8.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-72879?

CVE-2026-72879 is a documented vulnerability. Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and reg...

How severe is CVE-2026-72879?

CVSS scoring is not yet available for CVE-2026-72879. Check NVD for updates.

Is there a patch for CVE-2026-72879?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.