CVE-2026-72901 | Dokploy up to 0.29.12 Volume Backup backup.ts child_process.exec volumeName os command injection

SecurityVulns

A vulnerability identified as very critical has been detected in Dokploy up to 0.29.12. Affected by this vulnerability is the function child_process.exec of the file packages/server/src/utils/volume-backups/backup.ts of the component Volume Backup. The manipulation of the argument volumeName leads to os command injection.

This vulnerability is listed as CVE-2026-72901. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More