CVE-2026-45633
Critical · CVSS 9.9- CVSS
- 9.9
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-78
Description
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.
References
Status: profiled · ingested 2026-07-22T12:00:18.000Z