CVE-2025-64424High· 8.8▾ MidnightPoC availableCoolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a res…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.1%
1 GitHub repo (last check)
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available.
coolify < 4.0.0coolify = 4.0.0Upgrade past the affected range:
coolify 4.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-64419Critical· 9.6Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-34161High· 8.8Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow
CVE-2025-34159High· 8.8Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow
CVE-2025-34157Critical· 9.0Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow
CVE-2025-64425High· 8.1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-64422Medium· 4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases