{"id":"CVE-2025-64424","title":"Coolify is an open-source and self-hostable tool for managing servers, applications, and databases","summary":"Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a res…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-77"],"vendor":"coollabs","product":"coolify","affected":["coolify < 4.0.0","coolify = 4.0.0"],"patched":["coolify 4.0.0"],"published":"2026-01-05","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:10:00.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64424","references":[{"url":"https://drive.google.com/file/d/1rk7AYxNDkJUwo8uWbzX62PpBxpDYeyrZ/view?usp=drive_link","label":"security-advisories@github.com"},{"url":"https://github.com/coollabsio/coolify/security/advisories/GHSA-qx24-jhwj-8w6x","label":"security-advisories@github.com"},{"url":"https://github.com/coollabsio/coolify/security/advisories/GHSA-qx24-jhwj-8w6x","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.02092,"epssPercentile":0.80923,"exploits":{"github":1,"githubRepos":["https://github.com/androidteacher/CVE-2025-64424-Coolify-"],"checkedAt":"2026-09-30T22:28:02.731Z"},"exploitAvailable":true,"ingestedAt":"2026-09-30T22:27:27.694Z","slug":"CVE-2025-64424","body":"## Overview\n\nCoolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available.\n\n## Affected\n\n- `coolify < 4.0.0`\n- `coolify = 4.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `coolify 4.0.0`","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[]}