PT-2026-1335 · Coolify · Coolify

Published

2026-01-05

·

Updated

2026-01-12

·

CVE-2025-64424

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Coolify versions up to and including v4.0.0-beta.434
Description Coolify is a self-hostable tool for managing servers, applications, and databases. A command injection exists in the git source input fields of a resource, potentially allowing a low-privileged user (member) to execute system commands as root on the Coolify instance. The git source input fields are the point of entry for this issue.
Recommendations Versions prior to v4.0.0-beta.435 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-64424
GHSA-QX24-JHWJ-8W6X

Affected Products

Coolify