← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 17, 2026 · 15:02via CERT/CC Vulnerability Notes

VU#280377: Dokploy is vulnerable to OS command injection

Brief

Overview

Dokploy versions 0.

  • 8 and 0.
  • 11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privileges and lead to full compromise of the target device.

Description

Dokploy is an open-source Platform as a Service solution for deploying applications and databases on self-hosted servers. Dokploy allows authenticated users to create and schedule database backups and restore previously created backups. These backup operations are executed by the Dokploy process, which runs with root privileges by default.

Read more on CERT/CC Vulnerability Notes→