NONE · 0

CVE-2026-72885

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokploy/components/dashboard/application/build/show.tsx flows through getDockerConte...

Vulnerability Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokploy/components/dashboard/application/build/show.tsx flows through getDockerContextPath in packages/server/src/utils/filesystem/directory.ts into the unquoted cd command in packages/server/src/utils/builders/docker-file.ts before execution by execAsync, allowing an authenticated application editor to execute arbitrary commands on the Dokploy host. This issue is fixed in version 0.29.13.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-72885?

CVE-2026-72885 is a documented vulnerability. Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokploy/components/dashboard/application/build/show.tsx flows through getDockerConte...

How severe is CVE-2026-72885?

CVSS scoring is not yet available for CVE-2026-72885. Check NVD for updates.

Is there a patch for CVE-2026-72885?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.