Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project creation. By crafting a malicious service definition that mounts the host root filesystem, an attacker can gain full root access to the underlying server.
CVSS
No CVSS.
References
Configurations
No configuration.
History
27 Aug 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-27 17:15
Updated : 2025-08-27 17:15
NVD link : CVE-2025-34159
Mitre link : CVE-2025-34159
CVE.ORG link : CVE-2025-34159
JSON object : View
Products Affected
No product.