cbcvebase.

Coollabsio Coolify vulnerabilities

75 known vulnerabilities affecting coollabsio/coolify.

Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM20LOW6

Vulnerabilities

Page 1 of 4
CVE-2026-34594P2HIGHCVSS 8.8fixed in 4.0.0-beta.4712026-06-29
CVE-2026-34594 [HIGH] CWE-78 CVE-2026-34594: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network Management functionality allows users with destination management permissions to execute arbitrary commands as root on managed servers. The "network" para
nvd
CVE-2026-34038P2CRITICALCVSS 9.9fixed in 4.0.0-beta.4692026-07-06
CVE-2026-34038 [CRITICAL] CWE-78 CVE-2026-34038: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through
nvd
CVE-2025-66209P2HIGHCVSS 8.8fixed in 4.0.0-beta.4512025-12-23
CVE-2025-66209 [HIGH] CWE-78 CVE-2025-66209: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names us
nvd
CVE-2025-66212P2HIGHCVSS 8.8fixed in 4.0.0-beta.4512025-12-23
CVE-2025-66212 [HIGH] CWE-78 CVE-2025-66212: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Dynamic Proxy Configuration Filename handling allows users with application/service management permissions to execute arbitrary commands as root on managed servers. P
nvd
CVE-2025-66213P2HIGHCVSS 8.8fixed in 4.0.0-beta.4512025-12-23
CVE-2025-66213 [HIGH] CWE-78 CVE-2025-66213: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the File Storage Directory Mount Path functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers.
nvd
CVE-2026-34599P2HIGHCVSS 8.8fixed in 4.0.0-beta.4712026-07-06
CVE-2026-34599 [HIGH] CWE-78 CVE-2026-34599: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute arbitrary commands as root on managed servers. The $cont
nvd
CVE-2025-66211P2HIGHCVSS 8.8fixed in 4.0.0-beta.4512025-12-23
CVE-2025-66211 [HIGH] CWE-78 CVE-2025-66211: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in PostgreSQL Init Script Filename handling allows users with application/service management permissions to execute arbitrary commands as root on managed servers. PostgreSQL
nvd
CVE-2025-66210P2HIGHCVSS 8.8fixed in 4.0.0-beta.4512025-12-23
CVE-2025-66210 [HIGH] CWE-78 CVE-2025-66210: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Import functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names us
nvd
CVE-2026-27957P2HIGHCVSS 8.8fixed in 4.0.0-beta.4642026-06-30
CVE-2026-27957 [HIGH] CWE-78 CVE-2026-27957: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, an authenticated command injection vulnerability in the CA Certificate management feature allows any authenticated user to execute arbitrary commands as the configured SSH user on the managed server host. As the SSH user typically
nvd
CVE-2026-34597P2HIGHCVSS 8.8fixed in 4.0.0-beta.4702026-06-29
CVE-2026-34597 [HIGH] CWE-78 CVE-2026-34597: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.470, a critical Authenticated Host Remote Code Execution (RCE) vulnerability was discovered in Coolify. The flaw resides in the handling of user-defined build parameters for the Nixpacks build pack. Specifically, the install_command pr
nvd
CVE-2025-64424P2HIGHCVSS 8.8≤ 4.0.0-beta.4342026-01-05
CVE-2025-64424 [HIGH] CWE-77 CVE-2025-64424: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time
nvd
CVE-2025-22609P2CRITICALCVSS 10.0fixed in 4.0.0-beta.3612025-01-24
CVE-2025-22609 [CRITICAL] CWE-862 CVE-2025-22609: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server configuration of IP / domain, port (most likely 22) and user (root) mat
nvd
CVE-2025-22612P2CRITICALCVSS 10.0fixed in 4.0.0-beta.3742025-01-24
CVE-2025-22612 [CRITICAL] CWE-200 CVE-2025-22612: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server configuration of IP / domain, port (most likely 22) and user (root) match
nvd
CVE-2025-59157P2HIGHCVSS 8.8fixed in 4.0.0-beta.420.72026-01-05
CVE-2025-59157 [HIGH] CWE-78 CVE-2025-59157: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly sanitized, allowing attackers to inject arbitrary shell commands that execute on the underlying server durin
nvd
CVE-2025-59156P2HIGHCVSS 8.8fixed in 4.0.0-beta.420.72026-01-05
CVE-2025-59156 [HIGH] CWE-78 CVE-2025-59156: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to inject arbitrary Docker Compose directives during project creation or updates.
nvd
CVE-2026-34048P2CRITICALCVSS 9.9fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34048 [CRITICAL] CWE-285 CVE-2026-34048: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is
nvd
CVE-2026-59734P2HIGHCVSS 8.8fixed in 4.0.0-beta.4692026-07-09
CVE-2026-59734 [HIGH] CWE-78 CVE-2026-59734: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_method, and health_check_path parameters into shell commands without proper sanitiz
nvd
CVE-2026-34047P2CRITICALCVSS 9.9fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34047 [CRITICAL] CWE-863 CVE-2026-34047: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware, allowing an authenticated user to access terminal functionality for resources outside the authorized scope and potentially execute com
nvd
CVE-2026-84694P2HIGHCVSS 8.8fixed in 4.2.02026-09-02
CVE-2026-84694 [HIGH] CWE-78 CVE-2026-84694: Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands exec Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.
nvd
CVE-2026-42143P2HIGHCVSS 8.8fixed in 4.0.0-beta.4712026-07-07
CVE-2026-42143 [HIGH] CWE-78 CVE-2026-42143: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping or validation, allowing an authenticated member to inject shell metacharacters and execute commands as root
nvd