Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-45629

CRITICAL NVD
CVSS Score 9.9
Severity CRITICAL
Published May 29, 2026
Vendor unknown

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compromise.

References