Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privileges and lead to full compromise of the target device.
VU#280377: Dokploy is vulnerable to OS command injection
About this summary. This is a short, independently written summary of an article first published by CERT/CC. Cyber Security News did not report or verify the underlying story. Read the original: https://kb.cert.org/vuls/id/280377
Source attribution: headline and facts are from CERT/CC (kb.cert.org). Summary method: excerpt of the source description. See our source attribution policy and corrections policy.





