Vulnerability research & responsible disclosure
An authenticated user with backup:restore permission can execute arbitrary OS commands on the Dokploy host via an unquoted databaseName parameter. The injected command runs on the host shell before docker exec, bypassing container isolation and resulting in root-level code execution. Affects Dokploy <= 0.29.7.
Vendor: Dokploy
Vendors are notified privately and given time to patch before anything is published here.