CVE-2026-45662
Dokploy
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same file, the docker login command correctly uses shEscape() to prevent command injection. This inconsistency creates a command injection vulnerability when deleting a registry with a crafted registryUrl.
- CVSS
- 8.8
- EPSS
- 0.84% 54.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.30