CVE-2026-45790
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account with the owner role, while packages/server/src/services/user.ts allows a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover because owner roles cannot be demoted. This issue is fixed in version 0.29.6.
Schwachstellenklasse
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account with the owner role, while packages/server/src/services/user.ts allows a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover because owner roles cannot be demoted. This issue is fixed in version 0.29.6.
Quellen
- https://github.com/Dokploy/dokploy/commit/a07106d649991ea09892220873ea3243766c3e08
- https://github.com/Dokploy/dokploy/pull/4475
- https://github.com/Dokploy/dokploy/releases/tag/v0.29.6
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-fm9p-wmpw-gxjh
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-fm9p-wmpw-gxjh
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.