
CyberSec Daily ✓ · ☁️ DevSecOps · August 14, 2026 🎯 Dokploy vulnerability could allow commands to execute on the hosting server CVE-2026-72867 is a command-injection vulnerability affecting self-hosted Dokploy deployments. A low-privileged authenticated user could store a malicious Git branch value that is subsequently passed to a shell command during deployment, potentially compromising the server. Affected: 0.29.3–0.29.12 Fixed: 0.29.13 🔗 Source: SentinelOne Vulnerability Database #Dokploy #CVE202672867 #CommandInjection #DevSecOps #CloudSecurity
Post summary
The post announces a command‑injection vulnerability in Dokploy (CVE-2026-72867), details affected and fixed versions, and informs readers that the issue has been patched in 0.29.13.
