CVE-2026-72884

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts only trims whitespace and strips surrounding quotes from compose.command before exportEnvCommand and docker command interpolation, allowing an authenticated user who can update a Compose service to inject shell metacharacters and execute arbitrary commands on the Dokploy host. This issue is fixed in version 0.29.13.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 20:17

Updated : 2026-09-08 20:54


NVD link : CVE-2026-72884

Mitre link : CVE-2026-72884

CVE.ORG link : CVE-2026-72884


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')