Impact
Dokploy, a self‑hosted PaaS, allows user‑controlled data to be interpolated directly into shell commands via unquoted template literals in its registry credential testing and Docker Swarm cluster management endpoints. This flaw, a classic OS command injection (CWE‑77), permits an attacker to execute arbitrary commands on the host machine. The compromise affects confidentiality, integrity, and availability, effectively giving full control over the system.
Affected Systems
The vulnerability is present in Dokploy versions earlier than 0.29.13. All installations of Dokploy running a pre‑0.29.13 release are at risk. No additional sub‑product variants are noted.
Risk and Exploitability
With a CVSS score of 9.9, the flaw is classified as critical. The EPSS score is not available, but the lack of KEV listing suggests that widespread exploitation has not yet been observed. An attacker can exploit the vulnerability remotely by sending crafted requests to the affected endpoints; the attack path requires network access to the Dokploy server and the ability to invoke SSH commands on behalf of the service. The impact is local host compromise, leading to unrestricted code execution.
OpenCVE Enrichment