Critical severity9.9NVD Advisory· Published Aug 10, 2026
CVE-2026-72868
CVE-2026-72868
Description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection into an rclone ls command executed through child_process.exec. The withPermission("destination", "create") path permits a low-privileged organization member to reach the mutation, close a quoted argument with a crafted field, and execute arbitrary commands in the root Dokploy container, which has access to the host Docker socket. This issue is fixed in version 0.29.13.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.