Authenticated Command Injection Vulnerability in Coolify Tool by Coollabs
CVE-2025-66210
9.4CRITICAL
What is CVE-2025-66210?
Coolify, an open-source tool for server management, has a vulnerability in its Database Import functionality that allows authenticated users with certain permissions to execute arbitrary commands on the server. This is due to improper sanitization of database names that are passed directly to shell commands, leading to potential full remote code execution. The issue has been addressed in version 4.0.0-beta.451.
Affected Version(s)
coolify 0 < 4.0.0-beta.451
