Authenticated Host Remote Code Execution Vulnerability in Coolify by Coollabs
CVE-2026-34597

8.8HIGH

Key Information:

Vendor

Coollabsio

Status
Vendor
CVE Published:
29 June 2026

What is CVE-2026-34597?

Coolify, an open-source tool for managing servers and applications, is susceptible to a serious vulnerability that allows authenticated users to execute arbitrary commands on the host system. This occurs due to the unsafe handling of user-defined build parameters in the Nixpacks build pack. Specifically, the install_command input is directly integrated into a shell command executed on the deployment host. Attackers can exploit this flaw to break out of the build context, executing commands with host-level privileges. Users should upgrade to version 4.0.0-beta.470 or later to mitigate this security risk.

Affected Version(s)

coolify < 4.0.0-beta.470

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.