Coolify · Coolify · CVE-2025-66213
**Name of the Vulnerable Software and Affected Versions**
Coolify versions prior to 4.0.0-beta.451
**Description**
Coolify is a self-hostable tool for managing servers, applications, and databases. An authenticated command injection issue exists in the File Storage Directory Mount Path functionality. Users with application/service management permissions can execute arbitrary commands as root on managed servers. The `file storage directory source` parameter is passed to shell commands without proper sanitization, allowing for full remote code execution on the host system.
**Recommendations**
Upgrade to Coolify version 4.0.0-beta.451 or later.