These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in Coolify versions up to and including v4.0.0-beta.434 allows an attacker to initiate a password reset for a victim and modify the host header of the request to a malicious value. This can lead to the victim receiving a password reset email with a link to the malicious host, potentially allowing the attacker to capture the reset token and take over the victim's account.
A critical vulnerability exists in Coolify, an open-source tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability allows a low-privileged user (member) to execute system commands as root on the Coolify instance. This issue is particularly concerning as it could enable an attacker to gain elevated privileges and pot [truncated]
A low-privileged user in Coolify versions up to and including v4.0.0-beta.434 can escalate privileges to an administrator by using invitation links intended for administrators. This issue arises because low-privileged users can access and use invitation links meant for administrators before the intended recipient does, allowing them to log in as an administrator.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-05T21:16:12.403Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Coolify versions starting from 4.0.0-beta.434, allowing unlimited credential stuffing and brute-force attempts due to bypassable rate limiting on the /login endpoint. Defenders mana [truncated]
A low-privileged user can invite a high-privileged user in Coolify versions up to and including v4.0.0-beta.434. Initially, an error is thrown, but a second invitation attempt succeeds, allowing a low-privileged user to invite themselves as an administrator. The attacker can then initiate a password reset and log in as the new admin. This vulnerability allows for potential privilege escalation, emphasizin [truncated]
Low-privileged users in Coolify versions up to and including v4.0.0-beta.434 can view the private key of the root user. This allows them to authenticate as root via SSH using the private key. The vulnerability has a CVSS score of 9.9 and a Critical severity rating. As of the time of publication, it is unclear if a patch is available. Defenders managing Coolify instances should assess exposure and prioriti [truncated]
The CVE-2025-64419 vulnerability is a critical issue in Coolify, a self-hostable tool for managing servers, applications, and databases. The vulnerability allows for command injection due to unsanitized parameters from docker-compose.yaml used in commands. This can enable an attacker to execute commands as root on the Coolify instance if a victim user creates an application from an attacker repository. Th [truncated]
CVE-2025-59955 is an information disclosure vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. Versions prior to and including v4.0.0-beta.420.8 are affected. The vulnerability allows authenticated team members to access a highly sensitive `email_change_code` from other users on the same team via the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-05T18:15:43.790Z and has not been modified since then. The NVD entry is currently Analyzed. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a [truncated]
A critical vulnerability exists in Coolify, an open-source tool for managing servers, applications, and databases, prior to version 4.0.0-beta.420.7. The Git Repository field during project creation is vulnerable to command injection due to improper sanitization of user input. This allows attackers to inject arbitrary shell commands that execute on the underlying server during the deployment workflow. A r [truncated]
A critical vulnerability exists in Coolify, an open-source tool for managing servers, applications, and databases, prior to version 4.0.0-beta.420.7. This flaw allows a low-privileged member to inject arbitrary Docker Compose directives during project creation or updates, potentially leading to root-level command execution on the host OS by bypassing container isolation.