CVE-2025-34161
CVE-2025-34161
9.4
CriticalPublished:
Last updated:
Source:disclosure@vulncheck.com
Analyzed
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- Low
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- High
Description
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.
References
disclosure@vulncheck.com
https://coolify.io/disclosure@vulncheck.com
https://github.com/Eyodav/CVE-2025-34161disclosure@vulncheck.com
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.420.7