Unrated severityOSV Advisory· Published Jan 5, 2026· Updated Jan 5, 2026
Coolify members can see private key of root user
CVE-2025-64420
Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and authenticate as root user, using the private key. As of time of publication, it is unclear if a patch is available.
Affected products
1- Range: 4.0.0-beta.39, 4.0.0-beta.40, v1.0.0, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/coollabsio/coolify/security/advisories/GHSA-qwxj-qch7-whpcmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.