CVE-2025-59157Critical· 9.9▾ MidnightCoolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.8%
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly sanitized, allowing attackers to inject arbitrary shell commands that execute on the underlying server during the deployment workflow. A regular member user can exploit this vulnerability. Version 4.0.0-beta.420.7 contains a patch for the issue.
coolify < 4.0.0coolify = 4.0.0Upgrade past the affected range:
coolify 4.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-34161High· 8.8Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow
CVE-2025-59156High· 8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-64425High· 8.1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-64422Medium· 4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-64423High· 8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-64424High· 8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases