PT-2025-52856 · Coolify · Coolify

0Xrakan

·

Publicado

2025-12-23

·

Atualizado

2026-01-12

·

CVE-2025-66213

CVSS v4.0

9.4

Crítica

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.451
Description Coolify is a self-hostable tool for managing servers, applications, and databases. An authenticated command injection issue exists in the File Storage Directory Mount Path functionality. Users with application/service management permissions can execute arbitrary commands as root on managed servers. The file storage directory source parameter is passed to shell commands without proper sanitization, allowing for full remote code execution on the host system.
Recommendations Upgrade to Coolify version 4.0.0-beta.451 or later.

Exploit

Correção

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66213
GHSA-CJ2C-9JX8-J427

Produtos afetados

Coolify