CVE-2026-45633
🟠 Łataj w tym tygodniu
Wstrzyknięcie poleceń w Dokploy umożliwia uwierzytelnionym użytkownikom wykonanie dowolnych komend.
CVSS
9.9
EPSS
1.8%
Exploit
none
Vendor
Opis źródłowy (NVD)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.9 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.8% |
| Opublikowano (NVD) | 2026-05-29 18:17:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-06 22:10:00 UTC |