Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dokploy
Dokploy dokploy |
|
| Vendors & Products |
Dokploy
Dokploy dokploy |
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (which runs through /bin/sh -c). User-supplied branch names, repository URLs, and Docker credentials are interpolated directly into these commands without escaping. This requires an authenticated user with application create/edit privileges. | |
| Title | Dokploy: Command Injection via Unescaped Branch Fields in Deployment Pipeline | |
| Weaknesses | CWE-20 CWE-77 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T19:29:45.302Z
Reserved: 2026-05-12T20:31:43.449Z
Link: CVE-2026-45628
Updated: 2026-05-29T19:29:32.520Z
Status : Deferred
Published: 2026-05-29T18:17:10.807
Modified: 2026-05-29T20:25:00.760
Link: CVE-2026-45628
No data.
OpenCVE Enrichment
Updated: 2026-05-29T19:00:06Z