What is CVE-2026-72871?
CVE-2026-72871 is a critical vulnerability in Dokploy, a self-hostable PaaS. Before version 0.29.13, the unauthenticated `/api/providers/github/setup` endpoint blindly trusts `organizationId` and `userId` from the `state` parameter to create GitHub integrations. This could lead to remote code execution or unauthorized operations; immediate upgrade to version 0.29.13 or later is strongly recommended.
Azərbaycanca: CVE-2026-72871, Dokploy öz-özünə host edilən PaaS platformasında aşkarlanmış kritik boşluqdur. 0.29.13 versiyasından əvvəl, autentifikasiya olunmamış `/api/providers/github/setup` marşrutu `state` parametrindən gələn `organizationId` və `userId` dəyərlərinə şübhəsiz etibar edərək GitHub inteqrasiyası yaradılmasına imkan verir. Bu, uzaqdan kod icrası və ya icazəsiz əməliyyatlar riski yaradır, dərhal 0.29.13 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
FAQ2
What functionality of the Dokploy platform is affected by CVE-2026-72871?
CVE-2026-72871 affects the creation of GitHub integrations via the unauthenticated `/api/providers/github/setup` endpoint, where the `organizationId` and `userId` from the `state` parameter are blindly trusted.
What version of Dokploy is recommended to mitigate CVE-2026-72871?
Immediate upgrade to version 0.29.13 or later is strongly recommended to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.