Impact
An operator can trigger arbitrary operating system commands on the Dokploy host or a target server by supplying a Bitbucket owner or repository name that is not validated. The command string is concatenated directly into a git clone call, enabling classic OS command injection. The flaw permits an attacker with service deployment rights to hijack the deployment process and run malicious code, compromising confidentiality, integrity, and availability of the compromised infrastructure.
Affected Systems
Dokploy PaaS, version 0.29.12 and earlier. The vulnerability requires installation of Dokploy before the 0.29.13 release; any self‑hosted instance running a pre‑0.29.13 version is susceptible.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The Exploit Prediction System score is not available, but the lack of a registered KEV listing does not diminish the immediacy of the risk. The likely attack vector is a member possessing deployment permissions who can submit vulnerable Bitbucket details. Successful exploitation would allow them to execute any command on the host or target server, a high‑probability threat to systems managed by Dokploy.
OpenCVE Enrichment