CVE-2026-24841 | dokploy up to 0.26.5 WebSocket Endpoint docker-container-terminal containerId/activeWay os command injection (GHSA-vx6x-6559-x35r / CNNVD-202601-4838)
A vulnerability classified as critical was found in dokploy up to 0.26.5. This impacts an unknown function of the file /docker-container-terminal of the component WebSocket Endpoint. Such manipulation of the argument containerId/activeWay leads to os command injection.
This vulnerability is traded as CVE-2026-24841. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.