CVE-2026-45630

Published
View on NVD ↗
CVSS v3
9
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote servers via unsanitized echo shell interpolation.

Open Source Alternative to Vercel, Netlify and Heroku.
GitHubGitHub
35.1K