Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Dokploy — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting Dokploy. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dokploy serves as a deployment automation platform for web applications, enabling developers to streamline containerized service deployments. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, often stemming from improper input validation and access control weaknesses. The platform's seven recorded CVEs highlight recurring patterns in insecure default configurations and insufficient sanitization of user-supplied data. While no major public security incidents have been widely documented, the consistent discovery of critical vulnerabilities suggests ongoing challenges in secure coding practices and configuration management within the platform's architecture.

Top products by Dokploy: dokploy
Critical2026-08-11
Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById · Advisory · Dokploy/dokplo
CriticalCVE-2025-720012026-08-11
Remote Code Execution via volume-backup · Advisory · Dokploy/dokploy · GitHub
Unknown2026-08-11
fix(security): validate volumeName and escape volume-backup file names · Dokploy/dokploy@d629fae · GitHub
HighCVE-2025-728852026-08-11
Authenticated Command Injection in Dokploy Dockerfile Builder · Advisory · Dokploy/dokploy · GitHub
High2026-08-11
fix: prevent registry password from appearing in error messages and shell commands by Siumauricio · Pull Request #4579 ·
HighGHSA-gbqg-4mmj-m7h92026-08-11
fix(security): OS command injection in docker build/pull commands by Siumauricio · Pull Request #4860 · Dokploy/dokploy
High2026-08-11
fix: prevent registry password from appearing in error messages and s… · Dokploy/dokploy@1f4f940 · GitHub
High2026-08-11
fix(security): enforce owner/admin gate on host schedules regardless … · Dokploy/dokploy@1e3f10b · GitHub
High2026-08-11
fix(security): escape user input in docker build/pull commands · Dokploy/dokploy@cba0b25 · GitHub
CriticalCVE-2026-728862026-08-11
Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of
HighCVE-2026-720812026-08-11
Command Injection via database credentials in backup/restore commands · Advisory · Dokploy/dokploy · GitHub
HighCVE-2026-456322026-08-11
fix(security): host-schedule owner/admin bypass via applicationId (member → root) by Siumauricio · Pull Request #4869 ·
CriticalCVE-2020-720042026-08-11
Command Injection via Compose Custom Command · Advisory · Dokploy/dokploy · GitHub
UnknownCVE-2026-728652026-08-11
fix(security): OS command injection via compose path and custom command by Siumauricio · Pull Request #4863 · Dokploy/do
CriticalCVE-2024-728832026-08-11
WebSocket Terminal Missing Service-Level Access Control · Advisory · Dokploy/dokploy · GitHub
High2026-08-11
Reapply "feat(security): enforce service-level access on docker WebSo… · Dokploy/dokploy@1bc76e9 · GitHub
HighGHSA-c6ff-7wfp-g7v22026-08-11
fix(security): missing authorization on docker/terminal WebSocket handlers (member -> root) by Siumauricio · Pull Reques
High2026-08-11
fix(security): escape user-controlled values across command-injection sinks (quote sweep) by Siumauricio · Pull Request
High2026-08-11
fix(security): escape file paths and remote schedule command in shell… · Dokploy/dokploy@16b5b72 · GitHub
Critical2026-08-11
Arbitrary File Write + Remote OS Command Injection via `certificatePath` · Advisory · Dokploy/dokploy · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with Dokploy. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.