CVE-2026-45630: Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote servers via unsanitized echo shell interpolation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
dokployto a version that resolves this vulnerability.Fixed in 0.28.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45630?
CVE-2026-45630 has a critical severity rating of 9.
What vulnerabilities are associated with CVE-2026-45630?
CVE-2026-45630 is associated with OS Command Injection and Command Injection.
How do I fix CVE-2026-45630?
To fix CVE-2026-45630, update Dokploy to version 0.28.9 or later.
Who is affected by CVE-2026-45630?
CVE-2026-45630 affects users of Dokploy versions 0.28.8 and earlier who have admin or owner permissions.
What is the impact of CVE-2026-45630?
The impact of CVE-2026-45630 allows authenticated users to execute arbitrary system commands on remote servers.