These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability was detected in coollabsio Coolify up to 4.1.1, impacting an unknown function of the file /app/Policies/ of the Policy Handler component, leading to missing authorization. The exploit is public and remote exploitation is possible. This issue allows for unauthorized access, potentially leading to data breaches or system compromise. Users of coollabsio Coolify up to version 4.1.1 should veri [truncated]
CVE-2026-42201 is a low-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The issue, fixed in version 4.0.0-beta.474, involves inadequate validation of database credential fields, allowing potential command injection. This could lead to unauthorized access or malicious activity if exploited. Users of affected versions should apply the update to mitig [truncated]
Coolify, an open-source tool for managing servers, applications, and databases, has a vulnerability prior to version 4.0.0-beta.469. The executeInDocker() helper function does not properly escape user-controlled commands, allowing attackers to inject malicious commands during deployments. This issue is fixed in version 4.0.0-beta.469. The vulnerability allows attackers with the ability to edit application [truncated]
CVE-2026-42200 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the PostgreSQL initialization script, specifically in the generate_init_scripts() method in app/Actions/Database/StartPostgresql.php. The script's filename handling did not sufficiently restrict paths, allowing an authenticated user to write files o [truncated]
Coolify, an open-source tool for managing servers, applications, and databases, had an issue with Sanctum API tokens not expiring. This allowed leaked tokens to retain access indefinitely until manually revoked. The issue was fixed in version 4.0.0-beta.474. Affected users should verify their installations and update to the latest version to ensure token expiration. The vulnerability has a low CVSS score [truncated]
CVE-2026-42145 is a vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The file upload endpoint for database backup restore did not enforce file type or size validation, allowing authenticated users to upload unexpected or oversized files. This could affect service availability. The issue is fixed in version 4.0.0-beta.474.
Coolify, an open-source tool for managing servers, applications, and databases, had a high-severity vulnerability (CVSS Score: 8.8) allowing authenticated members to inject shell metacharacters and execute commands as root. This was due to user-controlled persistent volume names being interpolated into shell commands without proper escaping or validation. The issue was addressed in version 4.0.0-beta.471. [truncated]
CVE-2026-34198 is a medium-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The TrustProxies middleware trusts all proxies, accepting X-Forwarded-Host from any source. The TrustHosts middleware has a circular caching dependency that prevents host validation. This allows unauthenticated attackers to trigger password reset emails with links pointing t [truncated]
CVE-2026-34171 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the GET /invitations/{uuid} endpoint, which can perform a state-changing password reset using an attacker-known invitation UUID. This allows an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password [truncated]
CVE-2026-34170 is a vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The issue exists in versions prior to 4.0.0-beta.471, where the GithubApp api_url field is used as the base URL for server-side HTTP requests without allowlisting or private IP blocking. This allows an authenticated user to configure a GitHub App source that causes Coolify to request intern [truncated]
CVE-2026-34168 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability allows an authenticated user to execute commands on managed servers when a resource is deleted due to improper shell argument escaping in the LocalPersistentVolume.name field. This issue is fixed in version 4.0.0-beta.471. The vulnerability has a CVSS score o [truncated]
CVE-2026-34152 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability allows an authenticated user to inject additional shell statements that execute on the remote server during deployment. This issue was fixed in version 4.0.0-beta.471. Users should review deployment configurations and access controls. The vulnerability has a [truncated]
CVE-2026-34149 is a command injection vulnerability in Coolify's DatabaseBackupJob feature. Prior to version 4.0.0-beta.471, user-controlled database credentials and MongoDB collection exclusion names are interpolated into backup shell commands without adequate escaping. This allows an authenticated user with database management permissions to execute commands on managed servers. The vulnerability has a l [truncated]
CVE-2026-34058 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The Livewire component Server Resources exposes public methods that accept a container ID parameter directly from the browser without sanitization or escaping, allowing authenticated team members to execute arbitrary OS commands on remote servers. This issue affects Coolify ve [truncated]
CVE-2026-34057 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the database import Livewire component, where client-controlled container and server properties can reach shell commands without proper locking or validation. This allows an authenticated user to inject commands through a database import container n [truncated]
Coolify, an open-source tool for managing servers, applications, and databases, had a vulnerability in its terminal websocket bootstrap routes. This allowed a low-privileged team member to connect to terminal routes and execute commands on team servers due to insufficient authorization checks. The issue was fixed in version 4.0.0-beta.471. Users of Coolify should update to prevent unauthorized access. Thi [truncated]
CVE-2026-34047 is a critical vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce expected authorization middleware. This allowed an authenticated user to access terminal functionality for resources outside their authorized scope and potentially execute commands. The issue is fi [truncated]
CVE-2026-34044 is a high-severity vulnerability in Coolify's Logs::mount() component. Prior to version 4.0.0-beta.466, the component looks up resources by UUID without scoping the lookup to the current team. This allows an authenticated user to access logs for applications owned by other teams by supplying a victim resource UUID. The issue is fixed in version 4.0.0-beta.466. Affected users should update t [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-07T04:17:48.020Z and has not been modified since then. Coolify, an open-source tool for managing servers, applications, and databases, had a vulnerability in its cloneTo() Livewire action in ResourceOperations.php. Prior to version 4.0.0-beta.464, the action authorizes the source resource but resolv [truncated]
CVE-2026-34035 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability allows an authenticated user to inject commands executed on the host due to insufficient encoding of log drain secret and environment values into shell commands. This issue was fixed in version 4.0.0-beta.466. Affected deployments should be updated to prevent [truncated]
The CVE record for CVE-2026-34034 was published on 2026-07-07T04:17:47.603Z. The vulnerability affects Coolify versions prior to 4.0.0-beta.466, allowing an authenticated user to inject shell syntax and execute commands on the host. This issue is fixed in version 4.0.0-beta.466. Users of Coolify should review and update their installations to mitigate this vulnerability.
A high-severity vulnerability exists in Coolify versions 4.0.0-beta.471 through 4.0.0-beta.473 due to a regression in SHELL_SAFE_COMMAND_PATTERN. This allows an authenticated team member to inject shell commands that execute on the host. The issue is fixed in version 4.0.0-beta.474. Teams using affected versions should verify their inventory and apply the fix. The vulnerability has a CVSS score of 8.8 and [truncated]
CVE-2026-42153 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the PostgreSQL healthcheck command generation, where attacker-controlled database settings (postgres_user and postgres_db) are used in shell-form commands. This allows an authenticated user to inject commands executed in the database container, pote [truncated]
CVE-2026-42148 is a vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version field without shell escaping. This allows an attacker who can set the helper version and trigger the helper image build in a develop [truncated]
The Coolify API feedback endpoint was vulnerable to unauthenticated, unlimited, and unvalidated input, allowing attackers to forward arbitrary content to a Discord webhook. This issue was fixed in version 4.0.0-beta.474. The vulnerability could lead to spam, content injection, and webhook abuse. Users of affected versions should update to prevent potential abuse.
CVE-2026-34599 is an authenticated command injection vulnerability in the GetLogs Livewire component of Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability allows users with team membership, the lowest privilege member role, to execute arbitrary commands as root on managed servers. This is due to the $container Livewire public property being directly interpola [truncated]
CVE-2026-34167 is a vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The ActivityMonitor Livewire component exposes a public $activityId property without Livewire's #[Locked] attribute, allowing authenticated users to enumerate activity records across all teams and read full command output from remote SSH processes, potentially including secrets, configurati [truncated]
CVE-2026-34153 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.471, the LocalFileVolume::saveStorageOnServer function builds shell commands using unescaped fs_path and parent_dir values before validation. Additionally, the submitFileStorage function does not validate the user-controlled file-mount path before c [truncated]
CVE-2026-34050 is a medium-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The issue affects versions prior to 4.0.0-beta.471. The vulnerability resides in the Settings/Updates Livewire component, which fails to check if the user is an instance administrator (isInstanceAdmin) in its mount method. This oversight allows non-admin users to access the [truncated]
CVE-2026-32718 is a vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.466, the mutating API validation endpoints were guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating cloud tokens and servers. This issue was fixed in version 4.0.0-beta.466. The vulnerability allows una [truncated]
CVE-2026-34038 is a critical remote command injection vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the application deployment handling and allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through deployment logs via fields such as dockerfile_locatio [truncated]
CVE-2026-12815 is an OS command injection vulnerability in coollabsio coolify 4.0.0's Image Name Handler. Attackers can manipulate the image name to inject OS commands remotely. The vulnerability has a CVSS score of 2.1 and is considered low severity. The vendor, coollabsio, was contacted but did not respond. The changelog for version 4.1.2 mentions improved input validation for images, branches, proxies, [truncated]