A vulnerability classified as very critical was found in Dokploy up to 0.29.12. Impacted is the function
execAsync of the file packages/server/src/utils/builders/docker-file.ts of the component Docker Build. Executing a manipulation of the argument dockerContextPath can lead to improper synchronization.
This vulnerability appears as CVE-2026-72885. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.