{"id":"CVE-2026-72879","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72879","summary":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password…","details":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and registry.registryUrl directly into a shell command without escaping. An authenticated user with project access can configure malicious registry credentials and trigger a swarm deployment to execute arbitrary OS commands on the Dokploy server, read or modify host files, and access other containers through Docker. This issue is fixed in version 0.29.8.","published":"2026-08-10T20:17:34.420","modified":"2026-08-10T20:17:34.420","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/Dokploy/dokploy/commit/1f4f94042f1d874349c42d8ae7fee51346cd086e","label":"Dokploy/dokploy@1f4f940"},"references":[{"type":"WEB","url":"https://github.com/Dokploy/dokploy/commit/1f4f94042f1d874349c42d8ae7fee51346cd086e"},{"type":"WEB","url":"https://github.com/Dokploy/dokploy/pull/4579"},{"type":"WEB","url":"https://github.com/Dokploy/dokploy/releases/tag/v0.29.8"},{"type":"WEB","url":"https://github.com/Dokploy/dokploy/security/advisories/GHSA-prwq-2mcm-mvhr"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-10T20:17:34.420"}}