# CVE-2026-72867

## Summary

- **CVE ID:** CVE-2026-72867
- **Severity:** CRITICAL
- **CVSS Score:** 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-20, CWE-78, CWE-602
- **Published:** Aug 10, 2026
- **Last Modified:** Aug 13, 2026

## Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.update request to store a malicious customGitBranch, branch, gitlabBranch, bitbucketBranch, or giteaBranch. A low-privileged authenticated user can trigger compose.deploy, which passes the stored branch to shell-based Git clone commands in packages/server/src/utils/providers/git.ts, github.ts, gitlab.ts, bitbucket.ts, and gitea.ts, resulting in arbitrary host command execution. This issue is fixed in version 0.29.13.

## Affected Products

- Dokploy — dokploy (>= 0.29.3, < 0.29.13)

## References

- [CNA](https://github.com/Dokploy/dokploy/security/advisories/GHSA-cg8g-x23v-5fw8)
- [CNA](https://github.com/Dokploy/dokploy/pull/4855)
- [CNA](https://github.com/Dokploy/dokploy/commit/47347ab885b0ad1f5d0ef0e5e74bbba35c7f93bc)
- [CNA](https://github.com/Dokploy/dokploy/releases/tag/v0.29.13)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.49%
- **EPSS Percentile:** 40.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._