PT-2025-52853 · Coolify · Coolify

Andrasbacsai

·

Published

2025-12-23

·

Updated

2026-01-12

·

CVE-2025-66210

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.451
Description Coolify is a self-hostable tool for managing servers, applications, and databases. An authenticated command injection exists in the Database Import functionality, allowing users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in import operations are passed directly to shell commands without sanitization, enabling remote code execution. The vulnerable component is the database import functionality. The database name is a vulnerable parameter.
Recommendations Update to version 4.0.0-beta.451 or later.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-66210
GHSA-Q33H-22XM-4CGH

Affected Products

Coolify