CVE-2026-72870 | Dokploy up to 0.29.12 Docker Provider docker.ts buildRemoteDocker dockerImage os command injection
A vulnerability described as very critical has been identified in Dokploy up to 0.29.12. Impacted is the function buildRemoteDocker of the file packages/server/src/utils/providers/docker.ts of the component Docker Provider. Such manipulation of the argument dockerImage leads to os command injection.
This vulnerability is traded as CVE-2026-72870. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More