A vulnerability classified as very critical was found in Dokploy up to 0.29.12. Impacted is the function execAsync of the file packages/server/src/utils/builders/docker-file.ts of the component Docker Build. Executing a manipulation of the argument dockerContextPath can lead to improper synchronization.

This vulnerability appears as CVE-2026-72885. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.