What is CVE-2026-72873?
CVE-2026-72873 affects Dokploy, a self-hostable PaaS, where versions prior to 0.29.13 expose sensitive GitHub credentials (e.g., githubClientSecret) in API responses from `application.ts`. Users should update to version 0.29.13 or later immediately to address the information disclosure.
Azərbaycanca: CVE-2026-72873 Dokploy öz-özünə host edilə bilən PaaS platformasında aşkarlanıb. 0.29.13 versiyasından əvvəlki versiyalarda `application.ts` faylı `githubClientSecret` və `githubPrivateKey` kimi həssas məlumatları filtrləmədən qaytarır. İstifadəçilər dərhal 0.29.13 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Dokploy are affected by CVE-2026-72873?
This vulnerability affects all versions of Dokploy prior to 0.29.13.
What type of sensitive data is exposed in CVE-2026-72873?
Sensitive GitHub credentials such as `githubClientSecret` and `githubPrivateKey` are exposed in API responses via the `application.ts` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.