{"id":"CVE-2025-34161","title":"Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow","summary":"Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-20","CWE-78","CWE-78"],"vendor":"coollabs","product":"coolify","affected":["coolify < 4.0.0","coolify = 4.0.0"],"patched":["coolify 4.0.0"],"published":"2025-08-27","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34161","references":[{"url":"https://coolify.io/","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Eyodav/CVE-2025-34161","label":"disclosure@vulncheck.com"},{"url":"https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.420.7","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"epss":0.02963,"epssPercentile":0.86563,"ingestedAt":"2026-07-15T13:44:03.025Z","exploits":{"github":1,"githubRepos":["https://github.com/Eyodav/CVE-2025-34161"],"checkedAt":"2026-09-21T15:27:21.298Z"},"exploitAvailable":true,"slug":"CVE-2025-34161","body":"## Overview\n\nCoolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.\n\n## Affected\n\n- `coolify < 4.0.0`\n- `coolify = 4.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `coolify 4.0.0`","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.6,"exploitation":12,"ransomware":0},"changes":[{"seq":4817,"id":"CVE-2025-34161","ts":1788887208361,"field":"exploit_available","old":"false","new":"true"},{"seq":3700,"id":"CVE-2025-34161","ts":1788886325451,"field":"exploit_available","old":"true","new":"false"},{"seq":2545,"id":"CVE-2025-34161","ts":1788883007029,"field":"exploit_available","old":"false","new":"true"},{"seq":1574,"id":"CVE-2025-34161","ts":1788882407284,"field":"exploit_available","old":"true","new":"false"},{"seq":688,"id":"CVE-2025-34161","ts":1788881843998,"field":"exploit_available","old":"false","new":"true"}]}