Command Injection Vulnerability in Coolify by Coollabs
CVE-2025-66213

9.4CRITICAL

Key Information:

Vendor

Coollabsio

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-66213?

Coolify, a self-hosted tool for server and application management, contains an authenticated command injection vulnerability. This flaw affects versions prior to 4.0.0-beta.451, where the parameter 'file_storage_directory_source' is improperly sanitized, allowing users with specific permissions to execute arbitrary commands as root on the host system. The issue poses a significant security risk as it enables full remote code execution, potentially compromising the integrity and availability of managed servers. Users are urged to upgrade to the fixed version to mitigate this vulnerability.

Affected Version(s)

coolify 0 < 4.0.0-beta.451

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66213 : Command Injection Vulnerability in Coolify by Coollabs