---
id: CVE-2025-64423
title: >-
  Coolify is an open-source and self-hostable tool for managing servers,
  applications, and databases
summary: >-
  Coolify is an open-source and self-hostable tool for managing servers,
  applications, and databases. In Coolify versions up to and including
  v4.0.0-beta.434, a low privileged user (member) can see and use invitation
  links sent to an admin…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
vendor: coollabs
product: coolify
affected:
  - coolify < 4.0.0
  - coolify = 4.0.0
patched:
  - coolify 4.0.0
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64423'
references:
  - url: >-
      https://github.com/coollabsio/coolify/security/advisories/GHSA-4fqm-797g-7m6j
    label: security-advisories@github.com
  - url: >-
      https://github.com/coollabsio/coolify/security/advisories/GHSA-4fqm-797g-7m6j
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00342
epssPercentile: 0.25313
ingestedAt: '2026-09-30T22:27:27.694Z'
---

## Overview

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. When they use the link before the legitimate recipient does, they are able to log in as an administrator, meaning they have successfully escalated their privileges. As of time of publication, it is unclear if a patch is available.

## Affected

- `coolify < 4.0.0`
- `coolify = 4.0.0`

## Remediation

Upgrade past the affected range:

- `coolify 4.0.0`
