CVE-2026-24839

Published
View on NVD ↗
CVSS v3
4.7
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.

Open Source Alternative to Vercel, Netlify and Heroku.
GitHubGitHub
35.1K