PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64424 Coollabs CVE debrief

A critical vulnerability exists in Coolify, an open-source tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability allows a low-privileged user (member) to execute system commands as root on the Coolify instance. This issue is particularly concerning as it could enable an attacker to gain elevated privileges and potentially take control of the affected system.

Vendor
Coollabs
Product
Coolify
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-05
Original CVE updated
2026-09-30
Advisory published
2026-01-05
Advisory updated
2026-09-30

Who should care

System administrators, DevOps teams, and security professionals responsible for managing and securing Coolify instances should be aware of this vulnerability and take immediate action to patch or mitigate it.

Why it matters

This critical vulnerability in Coolify could allow low-privileged users to execute system commands as root, potentially leading to a complete compromise of the instance and connected systems. Defenders should prioritize patching, restrict access, and implement additional monitoring and logging to detect potential exploitation attempts.

  • Potential elevation of privileges for low-privileged users
  • Possible execution of arbitrary system commands as root
  • Potential compromise of the Coolify instance and connected systems
  • Need for verification of patch availability and application

Technical summary

A command injection vulnerability exists in the git source input fields of a resource in Coolify versions up to and including v4.0.0-beta.434, allowing a low-privileged user (member) to execute system commands as root on the Coolify instance. This issue is particularly concerning as it could enable an attacker to gain elevated privileges and potentially take control of the affected system. The vulnerability is confirmed based on official CVE Program and NVD records, and defenders should prioritize patching or mitigating this vulnerability as soon as possible.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability as soon as possible, especially in environments where low-privileged users have access to the Coolify instance.

Recommended defensive actions

  • Patch or upgrade to a version of Coolify that addresses this vulnerability.
  • Implement additional monitoring and logging to detect potential exploitation attempts.
  • Restrict access to the Coolify instance to only trusted users and networks.
  • Consider implementing compensating controls, such as Web Application Firewalls (WAFs), to help mitigate potential attacks.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is confirmed to exist in Coolify versions up to and including v4.0.0-beta.434, based on official CVE Program and NVD records. Defenders should verify patch availability, application, and implement additional monitoring to detect potential exploitation attempts. The CVE Program and NVD provide official records and assessments of this vulnerability, but the exact scope of affected systems and potential impact is still being investigated. Limited source detail is available, and defenders should exercise caution when rem

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64424 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64424

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64424 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64424

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-qx24-jhwj-8w6x

    [email protected] - Exploit, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.