cbcvebase.

Coollabsio Coolify vulnerabilities

75 known vulnerabilities affecting coollabsio/coolify.

Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM20LOW6

Vulnerabilities

Page 2 of 4
CVE-2026-34034P2HIGHCVSS 8.8fixed in 4.0.0-beta.4662026-07-07
CVE-2026-34034 [HIGH] CWE-78 CVE-2026-34034: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing an authenticated user with access to server Sentinel settings to inject shell syntax and execute commands on the host when Sentinel is re
nvd
CVE-2026-34037P3CRITICALCVSS 9.9fixed in 4.0.0-beta.4642026-07-07
CVE-2026-34037 [CRITICAL] CWE-639 CVE-2026-34037: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups, allowing an authenticated user to clone resources into destinations own
nvd
CVE-2026-57498P3CRITICALCVSS 9.6fixed in 4.0.0-beta.4742026-06-29
CVE-2026-57498 [CRITICAL] CWE-639 CVE-2026-57498: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parame
nvd
CVE-2026-34168P3HIGHCVSS 8.8fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34168 [HIGH] CWE-78 CVE-2026-34168: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument escaping, allowing an authenticated user to set a storage name containing shell metacharacters and execute comm
nvd
CVE-2026-34153P3HIGHCVSS 8.8fixed in 4.0.0-beta.4712026-07-06
CVE-2026-34153 [HIGH] CWE-78 CVE-2026-34153: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, LocalFileVolume::saveStorageOnServer builds shell commands using unescaped fs_path and parent_dir values before validation, and submitFileStorage does not validate the user-controlled file-mount path before creating a volume, allo
nvd
CVE-2025-22611P3CRITICALCVSS 9.9fixed in 4.0.0-beta.3612025-01-24
CVE-2025-22611 [CRITICAL] CWE-862 CVE-2025-22611: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalate his or any other team members privileges to any role, including the owner role. He's also able to kick every other member out of the team, including
nvd
CVE-2026-34158P3HIGHCVSS 8.8fixed in 4.0.0-beta.4692026-07-07
CVE-2026-34158 [HIGH] CWE-78 CVE-2026-34158: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping embedded single quotes. Attackers who can edit application settings can inject a single quote into docker_compose_custom_build_command o
nvd
CVE-2026-34058P3HIGHCVSS 8.8fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34058 [HIGH] CWE-78 CVE-2026-34058: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Livewire component Server\Resources exposes public methods (startUnmanaged, stopUnmanaged, restartUnmanaged) that accept a container ID parameter directly from the browser without any sanitization or escaping. This parameter i
nvd
CVE-2026-34152P3HIGHCVSS 8.8fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34152 [HIGH] CWE-78 CVE-2026-34152: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH heredoc transport that preserves newlines, allowing an authenticated user to inject additional shell statements that execute on the rem
nvd
CVE-2026-42153P3HIGHCVSS 8.8fixed in 4.0.0-beta.4742026-07-06
CVE-2026-42153 [HIGH] CWE-78 CVE-2026-42153: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an authenticated user to inject commands executed in the database container. Thi
nvd
CVE-2026-34057P3HIGHCVSS 8.8fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34057 [HIGH] CWE-78 CVE-2026-34057: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the database import Livewire component (app/Livewire/Project/Database/Import.php) allows client-controlled container and server properties to reach shell commands without locking or validation, allowing an authenticated user to in
nvd
CVE-2025-64420P3HIGHCVSS 8.8≤ 4.0.0-beta.4342026-01-05
CVE-2025-64420 [HIGH] CWE-522 CVE-2025-64420: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and authenticate as root user, using the private key. As of t
nvd
CVE-2026-42204P3HIGHCVSS 8.8v>= 4.0.0-beta.471, < 4.0.0-beta.4742026-07-06
CVE-2026-42204 [HIGH] CWE-78 CVE-2026-42204: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an authenticated team member to inject shell commands that ex
nvd
CVE-2026-42200P3HIGHCVSS 8.8fixed in 4.0.0-beta.4742026-07-07
CVE-2026-42200 [HIGH] CWE-22 CVE-2026-42200: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handling did not sufficiently restrict paths, allowing an authenticated user to write files outside the intende
nvd
CVE-2026-34035P3HIGHCVSS 8.8fixed in 4.0.0-beta.4662026-07-07
CVE-2026-34035 [HIGH] CWE-78 CVE-2026-34035: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands without sufficient encoding, allowing an authenticated user to inject commands executed on the host. This issue is fixed in version 4.0.0-beta.466.
nvd
CVE-2026-86117P3HIGHCVSS 8.1≤ 4.3.172026-09-05
CVE-2026-86117 [HIGH] CWE-287 CVE-2026-86117: Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as t
nvd
CVE-2025-64419P3HIGHCVSS 8.8fixed in 4.0.0-beta.4452026-01-05
CVE-2025-64419 [HIGH] CWE-77 CVE-2025-64419: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user creates an application from an attacker repository (using build pack "docker compose"), the attacker can execute commands
nvd
CVE-2025-64423P3HIGHCVSS 8.8≤ 4.0.0-beta.4342026-01-05
CVE-2025-64423 [HIGH] CWE-287 CVE-2025-64423: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. When they use the link before the legitimate recipient does, they are able to log in as an administrator, m
nvd
CVE-2026-100746P3HIGHCVSS 7.3v4.0v4.1.02026-09-27
CVE-2026-100746 [HIGH] CWE-287 CVE-2026-100746: A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redir A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be us
nvd
CVE-2026-12815P3MEDIUMCVSS 6.3v4.0.02026-06-22
CVE-2026-12815 [MEDIUM] CWE-77 CVE-2026-12815: A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the c A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way. The changelog for 4.1.2 mentions "[i]mproved ima
nvd
Coollabsio Coolify vulnerabilities | cvebase