PatchSiren

coollabsio CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM coollabsio CVE published 2026-07-06

CVE-2026-32718

CVE-2026-32718 is a vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.466, the mutating API validation endpoints were guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating cloud tokens and servers. This issue was fixed in version 4.0.0-beta.466. The vulnerability allows una [truncated]

CRITICAL coollabsio CVE published 2026-07-06

CVE-2026-34038

CVE-2026-34038 is a critical remote command injection vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the application deployment handling and allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through deployment logs via fields such as dockerfile_locatio [truncated]

LOW coollabsio CVE published 2026-06-22

CVE-2026-12815

CVE-2026-12815 is an OS command injection vulnerability in coollabsio coolify 4.0.0's Image Name Handler. Attackers can manipulate the image name to inject OS commands remotely. The vulnerability has a CVSS score of 2.1 and is considered low severity. The vendor, coollabsio, was contacted but did not respond. The changelog for version 4.1.2 mentions improved input validation for images, branches, proxies, [truncated]