{"id":"CVE-2026-72884","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72884","summary":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts only trims whitespace and strips surrounding…","details":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts only trims whitespace and strips surrounding quotes from compose.command before exportEnvCommand and docker command interpolation, allowing an authenticated user who can update a Compose service to inject shell metacharacters and execute arbitrary commands on the Dokploy host. This issue is fixed in version 0.29.13.","published":"2026-08-10T20:17:35.140","modified":"2026-08-10T20:17:35.140","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/Dokploy/dokploy/commit/d48037a80203bb0ecaec4f5653aef75fcfdb656d","label":"Dokploy/dokploy@d48037a"},"references":[{"type":"WEB","url":"https://github.com/Dokploy/dokploy/commit/d48037a80203bb0ecaec4f5653aef75fcfdb656d"},{"type":"WEB","url":"https://github.com/Dokploy/dokploy/pull/4863"},{"type":"WEB","url":"https://github.com/Dokploy/dokploy/releases/tag/v0.29.13"},{"type":"WEB","url":"https://github.com/Dokploy/dokploy/security/advisories/GHSA-qh6h-669j-77rw"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-10T20:17:35.140"}}