CRITICAL🇵🇱 Wersja polska

CVE-2025-64424

CVSS 9.4v4.0pub. 2026-01-05upd. 2026-01-12

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available.

🤖 AI Analysis
How it works

The CWE-77 (command injection) vulnerability consists of insufficient validation and sanitization of user-supplied data in configuration fields of the git source assigned to a resource. A user with the 'member' role (low privileges) can craft malicious input containing additional system commands. This data is then passed to system calls without proper escaping, resulting in execution with root privileges on the Coolify host.

Impact

An attacker with the 'member' role can execute arbitrary system commands with root privileges, leading to complete takeover of the Coolify instance, managed servers, applications, and databases.

Mitigation & patch

At the time of vulnerability publication, there was no certainty regarding patch availability. Track the official vendor repository and security advisory GHSA-qx24-jhwj-8w6x and apply patches according to vendor references immediately after release. Until updates are applied, it is recommended to restrict access to the Coolify instance only to trusted users and minimize the number of accounts with the 'member' role.

Who is affected

Coolify (Coollabs) in all versions up to v4.0.0-beta.434 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Coollabs Coolify

    APP
    Coollabs
    4.0.0< 4.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-59158CRITICAL9.4PL ✓same product

Stored XSS w Coolify — atak przez złośliwą nazwę projektu

CVE-2025-64419CRITICAL9.6PL ✓same product

Command injection w Coolify via docker-compose.yaml — RCE jako root

CVE-2025-59156CRITICAL9.4PL ✓same product

RCE w Coolify — command injection w konfiguracji Docker Compose

CVE-2025-59157CRITICAL9.9PL ✓same product

Command injection w polu Git Repository w Coolify

CVE-2025-64420CRITICAL9.9PL ✓same product

Coolify: nieuprawniony dostęp do prywatnego klucza SSH użytkownika root