PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64420 Coollabs CVE debrief

Low-privileged users in Coolify versions up to and including v4.0.0-beta.434 can view the private key of the root user. This allows them to authenticate as root via SSH using the private key. The vulnerability has a CVSS score of 9.9 and a Critical severity rating. As of the time of publication, it is unclear if a patch is available. Defenders managing Coolify instances should assess exposure and prioritize verification and mitigation, especially for systems with low-privileged user access.

Vendor
Coollabs
Product
Coolify
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-05
Original CVE updated
2026-09-30
Advisory published
2026-01-05
Advisory updated
2026-09-30

Who should care

Defenders managing Coolify instances, especially those with low-privileged user access, should assess exposure and prioritize verification and mitigation. This includes reviewing system configurations, restricting SSH access, and monitoring for unauthorized private key usage. Additionally, defenders should consider implementing compensating controls for systems with low-privileged user access and track exceptions and retest remediated assets.

Why it matters

CVE-2025-64420 is a Critical vulnerability in Coolify that allows low-privileged users to view the root private key, potentially leading to root authentication via SSH. Defenders should prioritize verification and mitigation, especially for systems with low-privileged user access.

  • Potential for low-privileged users to authenticate as root via SSH
  • Need for verification of exposure in Coolify versions up to v4.0.0-beta.434
  • Potential for unauthorized access to sensitive data and systems
  • Requirement for compensating controls due to potential lack of patch

Technical summary

Coolify, an open-source tool for managing servers, applications, and databases, has a vulnerability in versions up to and including v4.0.0-beta.434. Low-privileged users can view the private key of the root user, potentially allowing them to authenticate as root via SSH. The CVSS score is 9.9, with a Critical severity rating. This vulnerability allows for potential unauthorized access to sensitive data and systems, and defenders should prioritize verification and mitigation, especially for systems with low-privileged user access.

Defensive priority

Defenders should prioritize verifying exposure, especially for systems with low-privileged user access, and assess the need for compensating controls like restricting SSH access or monitoring for unauthorized private key usage.

Recommended defensive actions

  • Verify exposure by checking Coolify versions up to and including v4.0.0-beta.434
  • Restrict SSH access for low-privileged users
  • Monitor for unauthorized private key usage
  • Consider implementing compensating controls for systems with low-privileged user access
  • Review vendor guidance for patching or mitigating the vulnerability
  • Perform an asset inventory to identify potentially affected systems
  • Track exceptions and retest remediated assets

Evidence notes

The CVE Program record and NVD vulnerability detail provide official metadata and assessment. A source reference from [email protected] offers additional context. The vulnerability has been confirmed in Coolify versions up to and including v4.0.0-beta.434. Defenders should verify exposure and consider compensating controls due to the potential lack of a patch.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64420 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64420

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64420 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64420

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-qwxj-qch7-whpc

    [email protected] - Exploit, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.