CVE-2025-64424

Severity CVSS v4.0:
CRITICAL
Type:
CWE-77 Command Injection
Publication date:
05/01/2026
Last modified:
12/01/2026

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:* 4.0.0 (excluding)
cpe:2.3:a:coollabs:coolify:4.0.0:beta100:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta101:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta102:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta103:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta104:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta105:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta106:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta107:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta108:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta109:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta110:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta111:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta112:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta113:*:*:*:*:*:*