Vulnerabilidades em Dokploy

57 resultados
Análise Vexday

Dokploy apresenta um panorama de risco significativo com 18 vulnerabilidades registradas, sendo 11 críticas (CVSS ≥9.0) e 11 publicadas nos últimos 90 dias, indicando um padrão recente de descobertas. Embora nenhuma esteja sob exploração ativa documentada (KEV), a predominância de injeção de comando (CWE-78) representa um vetor de ataque direto e de alto impacto que demanda remediação prioritária. A concentração de críticas em período recente sugere questões estruturais na base de código que merecem revisão urgente.

CVE-2026-24841CRITICALDokploy Vulnerable to Authenticated Remote Code Execution via Command Injection in Docker Container Terminal WebSocket EndpointEPSS 2.8%CVE-2026-27130CRITICALDokploy has Command Injection in its Service OperationsEPSS 1.9%CVE-2026-45633CRITICALDokploy: Command Injection in /docker-container-logs EndpointEPSS 1.9%CVE-2026-45663CRITICALDokploy: Remote Code Execution via destinationPath in Container File UploadEPSS 1.6%CVE-2026-45662HIGHDokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)EPSS 1.6%CVE-2026-45629CRITICALDokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket EndpointEPSS 1.3%CVE-2026-45630CRITICALDokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo StatementEPSS 1.2%CVE-2025-53376MEDIUMDokploy allows attackers to run arbitrary OS commands on the Dokploy host.EPSS 1.1%CVE-2026-45661CRITICALDokploy: Remote Code Execution through Path TraversalEPSS 1.0%CVE-2026-72901CRITICALDokploy: Remote Code Execution via volume-backupEPSS 1.0%CVE-2026-72867CRITICALDokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts)EPSS 1.0%CVE-2026-72735CRITICALDokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote executionEPSS 0.9%CVE-2026-72885NONEDokploy: Authenticated Command Injection in Dokploy Dockerfile BuilderEPSS 0.8%CVE-2026-72875HIGHDokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFileEPSS 0.8%CVE-2026-72902CRITICALDokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIdEPSS 0.8%CVE-2026-72740CRITICALDokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan`EPSS 0.8%CVE-2026-72738CRITICALDokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search ParameterEPSS 0.8%CVE-2026-72733CRITICALDokploy: OS Command Injection via `databaseName` / `backupFile` in database restoreEPSS 0.7%CVE-2026-72876CRITICALDokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*EPSS 0.7%CVE-2026-72868CRITICALDokploy: Member-role RCE as host root via destination.testConnection rclone shell injectionEPSS 0.7%