CVE-2026-45633

🟠 Łataj w tym tygodniu

Wstrzyknięcie poleceń w Dokploy umożliwia uwierzytelnionym użytkownikom wykonanie dowolnych komend.

CVSS
9.9
EPSS
1.8%
Exploit
none
Vendor
Opis źródłowy (NVD)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.

rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.9
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.8%
Opublikowano (NVD)2026-05-29 18:17:11 UTC
Ostatnia modyfikacja (NVD)2026-10-06 22:10:00 UTC
Referencje