Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.
CVSS
No CVSS.
References
Configurations
No configuration.
History
27 Aug 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-27 17:15
Updated : 2025-08-27 17:15
NVD link : CVE-2025-34161
Mitre link : CVE-2025-34161
CVE.ORG link : CVE-2025-34161
JSON object : View
Products Affected
No product.