Vulnerabilities in Dokploy
53 resultsVexday analysis
Dokploy apresenta um panorama de risco significativo com 18 vulnerabilidades registradas, sendo 11 críticas (CVSS ≥9.0) e 11 publicadas nos últimos 90 dias, indicando um padrão recente de descobertas. Embora nenhuma esteja sob exploração ativa documentada (KEV), a predominância de injeção de comando (CWE-78) representa um vetor de ataque direto e de alto impacto que demanda remediação prioritária. A concentração de críticas em período recente sugere questões estruturais na base de código que merecem revisão urgente.
CVE-2026-72878CRITICALDokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsEPSS —CVE-2026-72736CRITICALDokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCEEPSS —CVE-2026-72902CRITICALDokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIdEPSS —CVE-2026-72862CRITICALDokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCEEPSS —CVE-2026-72872CRITICALDokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`EPSS —CVE-2026-72877CRITICALDokploy: Command Injection via dockerImage in buildRemoteDockerEPSS —CVE-2026-72735CRITICALDokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote executionEPSS —CVE-2026-72864CRITICALDokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers)EPSS —CVE-2026-72865CRITICALDokploy: OS Command Injection via compose `composePath`EPSS —CVE-2026-72868CRITICALDokploy: Member-role RCE as host root via destination.testConnection rclone shell injectionEPSS —CVE-2026-72867CRITICALDokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts)EPSS —CVE-2026-72901CRITICALDokploy: Remote Code Execution via volume-backupEPSS —CVE-2026-72871HIGHDokploy: Unauthenticated Git Provider Injection via GitHub OAuth CallbackEPSS —CVE-2026-72873MEDIUMDokploy: Cross-tenant Git provider secrets are disclosed to low-privileged service readers via `application.one`EPSS —CVE-2026-72886CRITICALDokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)EPSS —CVE-2026-72880CRITICALDokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath`EPSS —CVE-2026-72876CRITICALDokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*EPSS —CVE-2026-72869CRITICALDokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEEPSS —CVE-2026-72738CRITICALDokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search ParameterEPSS —CVE-2026-72733CRITICALDokploy: OS Command Injection via `databaseName` / `backupFile` in database restoreEPSS —