A vulnerability classified as very critical was found in Dokploy up to 0.29.12. Affected by this issue is the function backup.restoreBackupWithLogs of the file packages/server/src/utils/restore/utils.ts of the component Backup Restore. The manipulation of the argument databaseName/backupFile results in os command injection.

This vulnerability was named CVE-2026-72733. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.