Command Injection Vulnerability in Coolify by Coollabs
CVE-2025-66213
9.4CRITICAL
What is CVE-2025-66213?
Coolify, a self-hosted tool for server and application management, contains an authenticated command injection vulnerability. This flaw affects versions prior to 4.0.0-beta.451, where the parameter 'file_storage_directory_source' is improperly sanitized, allowing users with specific permissions to execute arbitrary commands as root on the host system. The issue poses a significant security risk as it enables full remote code execution, potentially compromising the integrity and availability of managed servers. Users are urged to upgrade to the fixed version to mitigate this vulnerability.
Affected Version(s)
coolify 0 < 4.0.0-beta.451
