PT-2025-52854 · Coolify · Coolify

0Xrakan

·

Published

2025-12-23

·

Updated

2026-01-12

·

CVE-2025-66211

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.451
Description Coolify is a self-hostable tool for managing servers, applications, and databases. A command injection issue exists in the handling of PostgreSQL Init Script Filenames. An authenticated user with application/service management permissions can execute arbitrary commands as root on managed servers. The issue occurs because PostgreSQL initialization script filenames are passed to shell commands without proper validation, enabling remote code execution.
Recommendations Update to version 4.0.0-beta.451 or later.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-66211
GHSA-24MP-FC9Q-C884

Affected Products

Coolify