CVE-2026-45663Critical· 9.9▾ MidnightDokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destina…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.6%
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly interpolated into a shell command string. By including shell metacharacters such as ; or ", an attacker can escape the intended docker cp command and execute arbitrary OS commands on the Dokploy host.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15139Medium· 6.3A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06
CVE-2025-15136High· 8.8A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0
CVE-2025-15137High· 8.8A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0
CVE-2025-15133Medium· 6.3A vulnerability was identified in ZSPACE Z4Pro+ 1.0.0440024
CVE-2025-15131Medium· 6.3A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024
CVE-2025-15132Medium· 6.3A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024