{"id":"CVE-2026-45662","title":"Dokploy is a free, self-hostable Platform as a Service (PaaS)","summary":"Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"published":"2026-05-29","updated":"2026-10-06","sourceUpdated":"2026-10-06T22:10:00.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45662","references":[{"url":"https://github.com/Dokploy/dokploy/security/advisories/GHSA-827c-7x62-29jq","label":"security-advisories@github.com"},{"url":"https://github.com/Dokploy/dokploy/security/advisories/GHSA-827c-7x62-29jq","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.01561,"epssPercentile":0.74438,"ingestedAt":"2026-10-06T22:23:15.927Z","slug":"CVE-2026-45662","body":"## Overview\n\nDokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same file, the docker login command correctly uses shEscape() to prevent command injection. This inconsistency creates a command injection vulnerability when deleting a registry with a crafted registryUrl.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}