Command Injection Vulnerability in Coolify by Cool Labs
CVE-2025-64424
9.4CRITICAL
What is CVE-2025-64424?
A command injection vulnerability has been identified in Coolify, an open-source platform designed for managing servers, applications, and databases. This flaw exists in the git source input fields, enabling a low-privileged user to execute arbitrary system commands with root privileges on the affected Coolify instance. At this time, there is no confirmed patch available to address this security risk.
Affected Version(s)
coolify <= 4.0.0-beta.434
