PT-2026-1335 · Coolify · Coolify

CVE-2025-64424

·

Publicado

2026-01-05

·

Atualizado

2026-01-12

CVSS v4.0

9.4

Crítica

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Coolify versions up to and including v4.0.0-beta.434
Description Coolify is a self-hostable tool for managing servers, applications, and databases. A command injection exists in the git source input fields of a resource, potentially allowing a low-privileged user (member) to execute system commands as root on the Coolify instance. The git source input fields are the point of entry for this issue.
Recommendations Versions prior to v4.0.0-beta.435 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-64424
GHSA-QX24-JHWJ-8W6X

Produtos afetados

Coolify