CVE-2026-45629
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compromise.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45629.json, https://github.com/Dokploy/dokploy/security/advisories/GHSA-r73h-qr3p-hf7f, https://nvd.nist.gov/vuln/detail/CVE-2026-45629