CVE-2026-32718 is a vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.466, the mutating API validation endpoints were guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating cloud tokens and servers. This issue was fixed in version 4.0.0-beta.466. The vulnerability allows una [truncated]
CVE-2026-34038 is a critical remote command injection vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the application deployment handling and allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through deployment logs via fields such as dockerfile_locatio [truncated]
CVE-2026-12815 is an OS command injection vulnerability in coollabsio coolify 4.0.0's Image Name Handler. Attackers can manipulate the image name to inject OS commands remotely. The vulnerability has a CVSS score of 2.1 and is considered low severity. The vendor, coollabsio, was contacted but did not respond. The changelog for version 4.1.2 mentions improved input validation for images, branches, proxies, [truncated]