Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Andrasbacsai

#13979of 53,633
19.3Total CVSS
Vulnerabilities · 2
Critical
2
PT-2025-52851
9.9
2025-12-23
Coolify · Coolify · CVE-2025-66209
**Name of the Vulnerable Software and Affected Versions** Coolify versions prior to 4.0.0-beta.451 **Description** Coolify is a self-hostable tool for managing servers, applications, and databases. A command injection issue exists in the Database Backup functionality for authenticated users with application/service management permissions. Database names used in backup operations are passed to shell commands without proper sanitization, potentially allowing execution of arbitrary commands as root on managed servers. **Recommendations** Update to version 4.0.0-beta.451 or later.
PT-2025-52853
9.4
2025-12-23
Coolify · Coolify · CVE-2025-66210
**Name of the Vulnerable Software and Affected Versions** Coolify versions prior to 4.0.0-beta.451 **Description** Coolify is a self-hostable tool for managing servers, applications, and databases. An authenticated command injection exists in the Database Import functionality, allowing users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in import operations are passed directly to shell commands without sanitization, enabling remote code execution. The vulnerable component is the database import functionality. The `database name` is a vulnerable parameter. **Recommendations** Update to version 4.0.0-beta.451 or later.