A vulnerability identified as very critical has been detected in Dokploy up to 0.29.12. Affected by this vulnerability is the function
child_process.exec of the file packages/server/src/utils/volume-backups/backup.ts of the component Volume Backup. The manipulation of the argument volumeName leads to os command injection.
This vulnerability is listed as CVE-2026-72901. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.