VYPR

Coolify

by Coollabsio

Source repositories

CVEs (73)

  • CVE-2026-34044HigJul 7, 2026
    risk 0.00cvss 7.7epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() component looks up resources by UUID without scoping the lookup to the current team, allowing an authenticated user to access logs for…

  • CVE-2026-34037CriJul 7, 2026
    risk 0.00cvss 9.9epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups,…

  • CVE-2026-34035HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands without sufficient encoding, allowing an authenticated user to inject…

  • CVE-2026-34034HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing an authenticated user with access to server Sentinel settings…

  • CVE-2026-42204HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command…

  • CVE-2026-42153HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an…

  • CVE-2026-42148LowJul 6, 2026
    risk 0.00cvss 3.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version field without shell…

  • CVE-2026-41899MedJul 6, 2026
    risk 0.00cvss 6.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and no input validation, allowing arbitrary content to be forwarded directly to a Discord…

  • CVE-2026-34599HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege…

  • CVE-2026-34167MedJul 6, 2026
    risk 0.00cvss 5.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor Livewire component exposes a public $activityId property without Livewire's #[Locked] attribute. It loads activities via…

  • CVE-2026-34153HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, LocalFileVolume::saveStorageOnServer builds shell commands using unescaped fs_path and parent_dir values before validation, and submitFileStorage does not…

  • CVE-2026-34050MedJul 6, 2026
    risk 0.00cvss 6.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to access the Updates settings page…

  • CVE-2026-34049LowJul 6, 2026
    risk 0.00cvss 3.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did not fully validate shell metacharacters, allowing a highly privileged…

  • CVE-2026-32718MedJul 6, 2026
    risk 0.00cvss 6.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating…

  • CVE-2026-34038CriJul 6, 2026
    risk 0.00cvss 9.9epss 0.02

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve…

  • CVE-2026-27957HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, an authenticated command injection vulnerability in the CA Certificate management feature allows any authenticated user to execute arbitrary commands as…

  • CVE-2026-27956MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/servers/{server_uuid}/domains?uuid={app_uuid}` bypasses team scoping when the optional uuid query parameter is provided. Any authenticated…

  • CVE-2026-27955MedJun 30, 2026
    risk 0.00cvss 6.6epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the executeInDocker() helper wraps commands in bash -c '{$command}' without escaping single quotes. User-controlled docker_compose_custom_build_command…

  • CVE-2026-27883MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deployments/{uuid}` endpoint allows any authenticated user to access deployment details belonging to any team, bypassing team-based…

  • CVE-2026-27882MedJun 30, 2026
    risk 0.00cvss 4.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.461, the GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. This implementation is…