Authenticated Command Injection Vulnerability in Coolify by CoolLabs
CVE-2025-66211
9.4CRITICAL
What is CVE-2025-66211?
Coolify, an open-source tool designed for server and application management, harbors a vulnerability in its PostgreSQL initialization script filename handling. This vulnerability allows users with permissions to manage applications or services to execute arbitrary commands with root privileges on the associated servers. The flaw arises from the lack of adequate validation for PostgreSQL initialization script filenames passed to the shell, which can lead to full remote code execution. Users are advised to upgrade to version 4.0.0-beta.451 or later to mitigate this risk.
Affected Version(s)
coolify 0 < 4.0.0-beta.451
