Coollabsio Coolify vulnerabilities
75 known vulnerabilities affecting coollabsio/coolify.
Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM20LOW6
Vulnerabilities
Page 3 of 4
CVE-2026-100744P3HIGHCVSS 7.3v4.1.0v4.1.1+1 more2026-09-27
CVE-2026-100744 [HIGH] CWE-862 CVE-2026-100744: A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function
A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading
nvd
CVE-2025-64425P3HIGHCVSS 8.1≤ 4.0.0-beta.4342026-01-05
CVE-2025-64425 [HIGH] CWE-644 CVE-2025-64425: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initiate a password reset for a victim, and modify the host header of the request to a malicious value. The victim will receive a password reset email, with a link to the malicious
nvd
CVE-2025-22606P3HIGHCVSS 7.8fixed in 4.0.0-beta.3592025-01-24
CVE-2025-22606 [HIGH] CWE-78 CVE-2025-22606: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In version 4.0.0-beta.358 and possibly earlier versions, when creating or updating a "project," it is possible to inject arbitrary shell commands by altering the project name. If a name includes unescaped characters, such as single quotes (`'`), it breaks
nvd
CVE-2026-34592P3HIGHCVSS 7.7fixed in 4.0.0-beta.4712026-06-29
CVE-2026-34592 [HIGH] CWE-639 CVE-2026-34592: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and project lookups are not scoped to the current team, allowing any authenticated user to access servers and projects belonging to other teams by specifying their IDs directly. This vulnerability is fixed in 4.0.0
nvd
CVE-2026-41896P3HIGHCVSS 7.5fixed in 4.0.0-beta.4742026-06-29
CVE-2026-41896 [HIGH] CWE-287 CVE-2026-41896: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the HMAC key is the application's manual_webhook_secret_github field, which is used by Coolify's webhook endpoints to validate incoming requests, is nullable with no default — meaning newly created applications have a null webhoo
nvd
CVE-2025-22605P3HIGHCVSS 7.8v>= 4.0.0-beta.18, < 4.0.0-beta.2532025-01-24
CVE-2025-22605 [HIGH] CWE-78 CVE-2025-22605: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Starting in version 4.0.0-beta.18 and prior to 4.0.0-beta.253, a vulnerability in the execution of commands on remote servers allows an authenticated user to execute arbitrary code on the local Coolify container, gaining access to data and private keys or
nvd
CVE-2025-64421P3HIGHCVSS 8.0≤ 4.0.0-beta.4342026-01-05
CVE-2025-64421 [HIGH] CWE-863 CVE-2025-64421: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can invite a high privileged user. At first, the application will throw an error, but if the attacker clicks the invite button a second time, it actually works. This
nvd
CVE-2026-34171P3HIGHCVSS 8.0fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34171 [HIGH] CWE-352 CVE-2026-34171: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account
nvd
CVE-2026-34044P3HIGHCVSS 7.7fixed in 4.0.0-beta.4662026-07-07
CVE-2026-34044 [HIGH] CWE-639 CVE-2026-34044: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() component looks up resources by UUID without scoping the lookup to the current team, allowing an authenticated user to access logs for applications owned by other teams by supplying a victim resource UUID. This
nvd
CVE-2025-59158P3HIGHCVSS 8.0fixed in 4.0.0-beta.420.72026-01-05
CVE-2025-59158 [HIGH] CWE-116 CVE-2025-59158: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can create a project with a maliciously
nvd
CVE-2026-41899P3MEDIUMCVSS 6.5fixed in 4.0.0-beta.4742026-07-06
CVE-2026-41899 [MEDIUM] CWE-306 CVE-2026-41899: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and no input validation, allowing arbitrary content to be forwarded directly to a Discord webhook and enabling spam, content injection, and webhook abuse. This issue i
nvd
CVE-2026-15507P3MEDIUMCVSS 6.3v4.1.0v4.1.12026-07-12
CVE-2026-15507 [MEDIUM] CWE-862 CVE-2026-15507: A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown f
A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit is now public and may be used.
nvd
CVE-2026-27955P3MEDIUMCVSS 6.6fixed in 4.0.0-beta.4642026-06-30
CVE-2026-27955 [MEDIUM] CWE-78 CVE-2026-27955: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the executeInDocker() helper wraps commands in bash -c '{$command}' without escaping single quotes. User-controlled docker_compose_custom_build_command and docker_compose_custom_start_command fields are interpolated directly, al
nvd
CVE-2026-32718P3MEDIUMCVSS 6.5fixed in 4.0.0-beta.4662026-07-06
CVE-2026-32718 [MEDIUM] CWE-863 CVE-2026-32718: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating cloud tokens and servers. This issue is fixed in version 4.0.0-beta.466.
nvd
CVE-2026-34050P3MEDIUMCVSS 6.5fixed in 4.0.0-beta.4712026-07-06
CVE-2026-34050 [MEDIUM] CWE-862 CVE-2026-34050: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to access the Updates settings page and potentially modify auto-update settings or trigger update checks. This
nvd
CVE-2025-22610P3MEDIUMCVSS 6.5fixed in 4.0.0-beta.3612025-01-24
CVE-2025-22610 [MEDIUM] CWE-862 CVE-2025-22610: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the global coolify instance OAuth configuration. This exposes the "client id" and "client secret" for every custom OAuth provider. The attacker can also m
nvd
CVE-2025-22608P4MEDIUMCVSS 6.5fixed in 4.0.0-beta.3612025-01-24
CVE-2025-22608 [MEDIUM] CWE-639 CVE-2025-22608: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke any team invitations on a Coolify instance by only providing a predictable and incrementing ID, resulting in a Denial-of-Service attack (DOS). Version 4.
nvd
CVE-2025-59955P4MEDIUMCVSS 5.7≤ 4.0.0-beta.4282026-01-05
CVE-2025-59955 [MEDIUM] CWE-201 CVE-2025-59955: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members` API endpoints allows authenticated team members to access a highly sensi
nvd
CVE-2026-27883P4MEDIUMCVSS 5.0fixed in 4.0.0-beta.4642026-06-30
CVE-2026-27883 [MEDIUM] CWE-639 CVE-2026-27883: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deployments/{uuid}` endpoint allows any authenticated user to access deployment details belonging to any team, bypassing team-based authorization. The $teamId is extracted from the authentication token but neve
nvd
CVE-2026-34167P4MEDIUMCVSS 5.0fixed in 4.0.0-beta.4712026-07-06
CVE-2026-34167 [MEDIUM] CWE-639 CVE-2026-34167: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor Livewire component exposes a public $activityId property without Livewire's #[Locked] attribute. It loads activities via Activity::find($this->activityId) with no authorization or team scoping. Activity IDs
nvd