---
id: CVE-2026-84694
title: >-
  Coolify before 4.2.0 fails to properly escape environment variable key names
  in Docker commands executed over SSH on managed servers
summary: >-
  Coolify before 4.2.0 fails to properly escape environment variable key names
  in Docker commands executed over SSH on managed servers. Authenticated
  attackers can inject shell metacharacters into environment variable keys to
  execute arbit…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-09-02'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84694'
references:
  - url: 'https://github.com/coollabsio/coolify'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/coollabsio/coolify/blob/v4.1.2/app/Policies/ApplicationPolicy.php
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/coollabsio/coolify/blob/v4.1.2/app/Support/ValidationPatterns.php
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/coollabsio/coolify/commit/b50839d4515b115b7ded5db609471440249995da
    label: disclosure@vulncheck.com
  - url: 'https://github.com/coollabsio/coolify/releases/tag/v4.2.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/coolify-before-4.2.0-remote-code-execution-via-environment-variable-key
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00845
epssPercentile: 0.56152
ingestedAt: '2026-09-10T16:57:28.700Z'
---

## Overview

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
