
CVE-2026-72880: Dokploy's certificatePath field accepts user input without confining it to the certificate root. An authenticated user can write files anywhere on the host or execute arbitrary OS commands. Fixed in 0.29.13. Upgrade now if you run Dokploy. https://hol.org/blog/cve-2026-72880-dokploy-cert-path-traversal-rce
Post summary
The advisory announces a path-traversal remote code execution flaw in Dokploy, highlights that version 0.29.13 contains a fix, and provides basic technical details of the vulnerability.

