Authenticated Command Injection Vulnerability in Coolify by CoolLabs
CVE-2025-66211

9.4CRITICAL

Key Information:

Vendor

Coollabsio

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-66211?

Coolify, an open-source tool designed for server and application management, harbors a vulnerability in its PostgreSQL initialization script filename handling. This vulnerability allows users with permissions to manage applications or services to execute arbitrary commands with root privileges on the associated servers. The flaw arises from the lack of adequate validation for PostgreSQL initialization script filenames passed to the shell, which can lead to full remote code execution. Users are advised to upgrade to version 4.0.0-beta.451 or later to mitigate this risk.

Affected Version(s)

coolify 0 < 4.0.0-beta.451

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66211 : Authenticated Command Injection Vulnerability in Coolify by CoolLabs