PatchSiren cyber security CVE debrief
CVE-2025-64420 Coollabs CVE debrief
Low-privileged users in Coolify versions up to and including v4.0.0-beta.434 can view the private key of the root user. This allows them to authenticate as root via SSH using the private key. The vulnerability has a CVSS score of 9.9 and a Critical severity rating. As of the time of publication, it is unclear if a patch is available. Defenders managing Coolify instances should assess exposure and prioritize verification and mitigation, especially for systems with low-privileged user access.
- Vendor
- Coollabs
- Product
- Coolify
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-05
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-05
- Advisory updated
- 2026-09-30
Who should care
Defenders managing Coolify instances, especially those with low-privileged user access, should assess exposure and prioritize verification and mitigation. This includes reviewing system configurations, restricting SSH access, and monitoring for unauthorized private key usage. Additionally, defenders should consider implementing compensating controls for systems with low-privileged user access and track exceptions and retest remediated assets.
Why it matters
CVE-2025-64420 is a Critical vulnerability in Coolify that allows low-privileged users to view the root private key, potentially leading to root authentication via SSH. Defenders should prioritize verification and mitigation, especially for systems with low-privileged user access.
- Potential for low-privileged users to authenticate as root via SSH
- Need for verification of exposure in Coolify versions up to v4.0.0-beta.434
- Potential for unauthorized access to sensitive data and systems
- Requirement for compensating controls due to potential lack of patch
Technical summary
Coolify, an open-source tool for managing servers, applications, and databases, has a vulnerability in versions up to and including v4.0.0-beta.434. Low-privileged users can view the private key of the root user, potentially allowing them to authenticate as root via SSH. The CVSS score is 9.9, with a Critical severity rating. This vulnerability allows for potential unauthorized access to sensitive data and systems, and defenders should prioritize verification and mitigation, especially for systems with low-privileged user access.
Defensive priority
Defenders should prioritize verifying exposure, especially for systems with low-privileged user access, and assess the need for compensating controls like restricting SSH access or monitoring for unauthorized private key usage.
Recommended defensive actions
- Verify exposure by checking Coolify versions up to and including v4.0.0-beta.434
- Restrict SSH access for low-privileged users
- Monitor for unauthorized private key usage
- Consider implementing compensating controls for systems with low-privileged user access
- Review vendor guidance for patching or mitigating the vulnerability
- Perform an asset inventory to identify potentially affected systems
- Track exceptions and retest remediated assets
Evidence notes
The CVE Program record and NVD vulnerability detail provide official metadata and assessment. A source reference from [email protected] offers additional context. The vulnerability has been confirmed in Coolify versions up to and including v4.0.0-beta.434. Defenders should verify exposure and consider compensating controls due to the potential lack of a patch.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-64420 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-64420
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-64420 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64420
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-qwxj-qch7-whpc
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.