CVE-2026-34037
published 2026-07-07CVE-2026-34037: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in…
PriorityP259critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAL
EPSS
0.44%
35.6th percentile
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups, allowing an authenticated user to clone resources into destinations owned by other teams and access cross-tenant resources. This issue is fixed in version 4.0.0-beta.464.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.464 | 4.0.0-beta.464 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
Suricata
ET WEB_SPECIFIC_APPS Linksys E-Series OS Command Injection (CVE-2025-34037) M1
suricata·2026-03-17·CVSS 10.0
CVE-2025-34037 [CRITICAL] ET WEB_SPECIFIC_APPS Linksys E-Series OS Command Injection (CVE-2025-34037) M1
ET WEB_SPECIFIC_APPS Linksys E-Series OS Command Injection (CVE-2025-34037) M1
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Linksys E-Series OS Command Injection (CVE-2025-34037) M1"; flow:established,to_server; http.uri; content:"/tmUnblock.cgi"; fast_pattern; http.request_body; content:"ttcp_ip|3d|"; pcre:"/^[^&]*?(?:[\x3b\x24\x26\x60\x7c]|\x25(?:3[bB]|2[46]|60|7[cC]))/R"; http.method; content:"POST"; reference:url,www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis; reference:cve,2025-34037; classtype:web-application-attack; sid:2068292; rev:1; metadata:affected_product Linksys, attack_target Server, tls_state TLSDecrypt, created_at 2026_03_17, cve CVE_2025_34037, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signat
Suricata
ET WEB_SPECIFIC_APPS Linksys E-Series OS Command Injection (CVE-2025-34037) M2
suricata·2026-03-17·CVSS 10.0
CVE-2025-34037 [CRITICAL] ET WEB_SPECIFIC_APPS Linksys E-Series OS Command Injection (CVE-2025-34037) M2
ET WEB_SPECIFIC_APPS Linksys E-Series OS Command Injection (CVE-2025-34037) M2
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Linksys E-Series OS Command Injection (CVE-2025-34037) M2"; flow:established,to_server; http.uri; content:"/hndUnblock.cgi"; fast_pattern; http.request_body; content:"ttcp_ip|3d|"; pcre:"/^[^&]*?(?:[\x3b\x24\x26\x60\x7c]|\x25(?:3[bB]|2[46]|60|7[cC]))/R"; http.method; content:"POST"; reference:url,www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis; reference:cve,2025-34037; classtype:web-application-attack; sid:2068293; rev:1; metadata:affected_product Linksys, attack_target Server, tls_state TLSDecrypt, created_at 2026_03_17, cve CVE_2025_34037, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signa
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coollabsio/coolify/commit/1759a1631cd63271ebf6caa250c6d93440eaa333https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.464https://github.com/coollabsio/coolify/security/advisories/GHSA-ggrr-wrvr-x83vhttps://github.com/coollabsio/coolify/security/advisories/GHSA-ggrr-wrvr-x83v
2026-07-07
Published