CVE-2026-72873

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts returns provider relations loaded by findApplicationById in packages/server/src/services/application.ts without redacting githubClientSecret, githubPrivateKey, or githubWebhookSecret, allowing a user with only service:read permission to retrieve another user’s Git provider secrets even when hasGitProviderAccess is false and unauthorizedProvider is set. This issue is fixed in version 0.29.13.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 20:17

Updated : 2026-09-08 20:54


NVD link : CVE-2026-72873

Mitre link : CVE-2026-72873

CVE.ORG link : CVE-2026-72873


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor