CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-45633

Critical · CVSS 9.9
CVSS
9.9
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-78

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.

References

Status: profiled · ingested 2026-07-22T12:00:18.000Z