A vulnerability described as very critical has been identified in Dokploy up to 0.29.12. This affects the function createCommand. The manipulation results in os command injection.

This vulnerability is known as CVE-2026-72739. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.