What is CVE-2026-72874?
In Dokploy versions prior to 0.29.13, an authenticated user can execute arbitrary commands on the server via a crafted git URL due to improper input sanitization in the `cloneGitRepository` function during `git clone` operations. To mitigate this, an immediate upgrade to the latest version is strongly recommended.
Azərbaycanca: Dokploy-un 0.29.13-dən əvvəlki versiyalarında autentifikasiya olunmuş istifadəçi xüsusi git URL-i vasitəsilə serverdə ixtiyari əmrlər icra edə bilər. Bu, `cloneGitRepository` funksiyasında `git clone` əməliyyatı zamanı daxiletmənin düzgün təmizlənməməsindən qaynaqlanır. İstismarın qarşısını almaq üçün dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
How can an authenticated user execute arbitrary commands on the server in Dokploy versions prior to 0.29.13?
An authenticated user can execute arbitrary commands on the server via a crafted git URL due to improper input sanitization in the `cloneGitRepository` function during `git clone` operations.
What is recommended to mitigate CVE-2026-72874?
To mitigate this, an immediate upgrade to the latest version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.