← Back to browse · API

CVE-2025-59157

Severity
CRITICAL
CVSS
10.0
EPSS
0.0183
Risk score
40.64
CISA KEV
No
PoC
No
Published
2026-01-05
Modified
2026-01-05
First seen
2026-08-07
Aliases
EUVD-2025-206243
Products
coollabsio:coolify < 4.0.0-beta.420.7
Sources
euvd EUVD-2025-206243

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly sanitized, allowing attackers to inject arbitrary shell commands that execute on the underlying server during the deployment workflow. A regular member user can exploit this vulnerability. Version 4.0.0-beta.420.7 contains a patch for the issue.

References