CRITICAL🇵🇱 Wersja polska

CVE-2025-59156

CVSS 9.4v4.0pub. 2026-01-05upd. 2026-01-12

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to inject arbitrary Docker Compose directives during project creation or updates. By defining a malicious service that mounts the host filesystem, an attacker can achieve root-level command execution on the host OS, completely bypassing container isolation. Version 4.0.0-beta.420.7 contains a patch for the issue.

🤖 AI Analysis
How it works

An attacker with the role of a regular project member can define a malicious service in the Docker Compose configuration, mounting the host file system inside the container. This allows them to gain access to host resources outside the container environment. This results in privilege escalation to root level on the host operating system and complete takeover of the machine.

Impact

An attacker can obtain execution of arbitrary code with root privileges on the host (RCE), leading to complete server takeover, loss of data confidentiality, and violation of integrity and availability of all systems running on that host.

Mitigation & patch

Coolify should be updated to version 4.0.0-beta.420.7 or newer, which contains a patch resolving the issue. According to the vendor's references, an advisory is available at https://github.com/coollabsio/coolify/security/advisories/GHSA-h5xw-7xvp-xrxr

Who is affected

Coolify (Coollabs) in versions earlier than 4.0.0-beta.420.7

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Coollabs Coolify

    APP
    Coollabs
    4.0.0< 4.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEContainerCommand Injection
CWE
References

Related vulnerabilities

CVE-2025-64419CRITICAL9.6PL ✓same product

Command injection w Coolify via docker-compose.yaml — RCE jako root

CVE-2025-64420CRITICAL9.9PL ✓same product

Coolify: nieuprawniony dostęp do prywatnego klucza SSH użytkownika root

CVE-2025-59157CRITICAL9.9PL ✓same product

Command injection w polu Git Repository w Coolify

CVE-2025-59158CRITICAL9.4PL ✓same product

Stored XSS w Coolify — atak przez złośliwą nazwę projektu

CVE-2025-64424CRITICAL9.4PL ✓same product

Command injection w Coolify — wykonanie poleceń jako root przez użytkownika