CVE-2025-34159
published 2025-08-27CVE-2025-34159: Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.96%
59.6th percentile
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project creation. By crafting a malicious service definition that mounts the host root filesystem, an attacker can gain full root access to the underlying server.
Affected
409 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coollabs | coolify | < 4.0.0 | 4.0.0 |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
| coollabs | coolify | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
coollabsio Coolify up to 4.0.0-beta.420.5 code injection
vuldb·2026-07-15·CVSS 8.8
CVE-2025-34159 [HIGH] coollabsio Coolify up to 4.0.0-beta.420.5 code injection
A vulnerability was found in coollabsio Coolify up to 4.0.0-beta.420.5. It has been classified as critical. This vulnerability affects unknown code. The manipulation leads to code injection.
This vulnerability is traded as CVE-2025-34159. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-qh8c-f279-4cgv: Coolify versions prior to v4
ghsa_unreviewed·2025-08-27
CVE-2025-34159 [CRITICAL] CWE-20 GHSA-qh8c-f279-4cgv: Coolify versions prior to v4
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project creation. By crafting a malicious service definition that mounts the host root filesystem, an attacker can gain full root access to the underlying server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-27
Published