← Terug naar overzicht

A path traversal vulnerability has been identified in Dokploy up to version 0.29.7. The flaw exists in the writeTraefikConfigInPath function within packages/server/src/utils/traefik/application.ts in the Settings component. An attacker can manipulate the path argument to traverse directories outside the intended scope. The vulnerability is remotely exploitable without requiring physical access. A public exploit is already available, increasing the risk of active exploitation. The vendor was contacted prior to disclosure but did not respond, leaving users without an official patch or mitigation. This represents a significant risk to deployments running affected versions of Dokploy. Users are advised to restrict access and monitor for suspicious file access patterns until a fix is available.

Affected products

  • Dokploy 0.29.7

Related CVE's

  • CVE-2026-82954

Categories

  • Cloud & Virtualization
  • Web Technologies
  • Zero-Day Vulnerabilities