Back to home

CVEs

Vulnerability research & responsible disclosure

9.9CVSS
GHSA-f7mp-9jfp-mjrrCritical2026-07

Authenticated OS command injection in Dokploy backup restore leading to host RCE

An authenticated user with backup:restore permission can execute arbitrary OS commands on the Dokploy host via an unquoted databaseName parameter. The injected command runs on the host shell before docker exec, bypassing container isolation and resulting in root-level code execution. Affects Dokploy <= 0.29.7.

Vendor: Dokploy

Advisory

Vendors are notified privately and given time to patch before anything is published here.