Junglewise Threat Intelligence

CVE-2026-45630: Dokploy OS command injection in updateTraefikConfig

CVE-2026-45630 · Severity: critical · CVSS 9 · Published 2026-05-29

Technologies: Dokploy. Vendors: Dokploy.

Executive brief

Dokploy is a self-hostable platform used to manage and deploy applications. A security flaw allows administrative users to execute unauthorized system commands on the servers managed by the platform. This could lead to a complete takeover of the underlying infrastructure and access to sensitive application data.

Technical details

An OS command injection vulnerability exists in the `application.updateTraefikConfig` tRPC endpoint within Dokploy. The root cause is the lack of sanitization for the `traefikConfig` input, which is subsequently interpolated into a shell `echo` command executed via SSH in the `writeConfigRemote` function. An attacker with admin or owner privileges can use a single quote to break out of the shell quoting context and inject arbitrary commands. This results in remote code execution (RCE) with the privileges of the SSH user on managed servers.

Affected products

  • Dokploy Dokploy <= 0.28.8

Timeline

  • 2026-05-11: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: CVE published to NVD

References

Related threats