CVE-2026-72902: Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server because registry.testRegistry and registry.testRegistryById in apps/dokploy/server/api/routers/registry.ts interpolate the password field into an execAsyncRemote shell command instead of using safeDockerLoginCommand. This issue is fixed in version 0.29.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dokployto a version that resolves this vulnerability.Fixed in 0.29.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72902?
CVE-2026-72902 has a critical severity rating of 9.9.
How do I fix CVE-2026-72902?
To fix CVE-2026-72902, upgrade to Dokploy version 0.29.13 or later.
What type of vulnerability is CVE-2026-72902?
CVE-2026-72902 is an OS Command Injection vulnerability.
What are the potential impacts of CVE-2026-72902?
CVE-2026-72902 allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server.
What applications are affected by CVE-2026-72902?
CVE-2026-72902 affects Dokploy versions prior to 0.29.13.