CVE-2026-72865 | Dokploy up to 0.29.12 Compose compose.ts compose.update composePath os command injection
A vulnerability, which was classified as very critical, was found in Dokploy up to 0.29.12. This impacts the function compose.update of the file packages/server/src/utils/builders/compose.ts of the component Compose. The manipulation of the argument composePath results in os command injection.
This vulnerability was named CVE-2026-72865. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More