CVE-2026-72867Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.update request to store a malicious customGitBranch, branch, gitlabBranch, bitbucketBranch, or giteaBranch. A low-privileged authenticated user can trigger compose.deploy, which passes the stored branch to shell-based Git clone commands in packages/server/src/utils/providers/git.ts, github.ts, gitlab.ts, bitbucket.ts, and gitea.ts, resulting in arbitrary host command execution. This issue is fixed in version 0.29.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78CWE-602

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-14: 2Patch / Workaround · 2026-08-14: 2Technical Details · 2026-08-14: 208-14
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Full discourse2 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    CyberSec Daily ✓ · ☁️ DevSecOps · August 14, 2026 🎯 Dokploy vulnerability could allow commands to execute on the hosting server CVE-2026-72867 is a command-injection vulnerability affecting self-hosted Dokploy deployments. A low-privileged authenticated user could store a malicious Git branch value that is subsequently passed to a shell command during deployment, potentially compromising the server. Affected: 0.29.3–0.29.12 Fixed: 0.29.13 🔗 Source: SentinelOne Vulnerability Database #Dokploy #CVE202672867 #CommandInjection #DevSecOps #CloudSecurity

    Post summary

    The post announces a command‑injection vulnerability in Dokploy (CVE-2026-72867), details affected and fixed versions, and informs readers that the issue has been patched in 0.29.13.

    0000036
    59 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSec Daily ✓ · 🐳 Cloud Security · August 14, 2026 🎯 Dokploy command-injection vulnerability could compromise the hosting server A vulnerability tracked as CVE-2026-72867 affects the self-hosted Dokploy platform. A low-privileged authenticated user could inject a malicious Git branch value that is subsequently passed to a shell command during deployment. Successful exploitation could execute arbitrary commands on the Dokploy host and compromise the PaaS control plane. Affected: Dokploy 0.29.3–0.29.12 Fixed: Dokploy 0.29.13 🔗 Source: SentinelOne Vulnerability Database #Dokploy #CVE202672867 #CommandInjection #CloudSecurity #DevSecOps

    Post summary

    This post announces a command‑injection vulnerability (CVE-2026-72867) in Dokploy that allows low‑privileged authenticated users to execute arbitrary commands on the host, and notes that the issue is fixed in version 0.29.13; no active exploitation is reported.

    0000049
    59 followersView on X

Explore more