A vulnerability was found in Dokploy up to 0.29.12. It has been declared as very critical. Impacted is the function buildRemoteDocker of the file packages/server/src/utils/providers/docker.ts of the component Docker Provider. The manipulation of the argument dockerImage results in os command injection.

This vulnerability is identified as CVE-2026-72877. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.