← Back to browse · API

CVE-2026-24841

Severity
CRITICAL
CVSS
9.9
EPSS
0.02518
Risk score
40.48
CISA KEV
No
PoC
No
Published
2026-01-28
Modified
2026-01-28
First seen
2026-08-07
Aliases
EUVD-2026-4907
Products
Dokploy:dokploy < 0.26.6
Sources
euvd EUVD-2026-4907

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokploy's WebSocket endpoint `/docker-container-terminal`. The `containerId` and `activeWay` parameters are directly interpolated into shell commands without sanitization, allowing authenticated attackers to execute arbitrary commands on the host server. Version 0.26.6 fixes the issue.

References