VYPR
Unrated severityOSV Advisory· Published Jan 5, 2026· Updated Jan 5, 2026

Colify has command injection vulnerability in project git source

CVE-2025-64424

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Coollabsio/CoolifyOSV2 versions
    4.0.0-beta.39, 4.0.0-beta.40, v1.0.0, …+ 1 more
    • (no CPE)range: 4.0.0-beta.39, 4.0.0-beta.40, v1.0.0, …
    • (no CPE)range: <=4.0.0-beta.434

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.