VYPR

Vendor CVEs

Coollabsio

All CVEs

73 total · sorted by risk
  • CVE-2025-22612CriJan 24, 2025
    risk 0.65cvss 10.0epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server…

  • CVE-2025-22609CriJan 24, 2025
    risk 0.65cvss 10.0epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server…

  • CVE-2025-64420CriJan 5, 2026
    risk 0.64cvss 9.9epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh…

  • CVE-2025-59157CriJan 5, 2026
    risk 0.64cvss 9.9epss 0.02

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly sanitized, allowing attackers to…

  • CVE-2025-22611CriJan 24, 2025
    risk 0.64cvss 9.9epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalate his or any other team members privileges to any role, including the owner…

  • CVE-2025-34157CriAug 27, 2025
    risk 0.59cvss 9.0epss 0.00

    Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an…

  • CVE-2025-64424HigJan 5, 2026
    risk 0.57cvss 8.8epss 0.02

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user…

  • CVE-2025-64423HigJan 5, 2026
    risk 0.57cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. When they use the link before…

  • CVE-2025-59156HigJan 5, 2026
    risk 0.57cvss 8.8epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

  • CVE-2025-34159HigAug 27, 2025
    risk 0.57cvss 8.8epss 0.01

    Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project…

  • CVE-2025-64425HigJan 5, 2026
    risk 0.53cvss 8.1epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initiate a password reset for a victim, and modify the host header of the request to a malicious value.…

  • CVE-2025-64421HigJan 5, 2026
    risk 0.52cvss 8.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can invite a high privileged user. At first, the application will throw an error, but if…

  • CVE-2025-59158HigJan 5, 2026
    risk 0.52cvss 8.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with…

  • CVE-2025-22606HigJan 24, 2025
    risk 0.51cvss 7.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In version 4.0.0-beta.358 and possibly earlier versions, when creating or updating a "project," it is possible to inject arbitrary shell commands by altering the project name. If…

  • CVE-2025-22610MedJan 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the global coolify instance OAuth configuration. This exposes the "client id" and…

  • CVE-2025-22608MedJan 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke any team invitations on a Coolify instance by only providing a predictable and…

  • CVE-2026-12815MedJun 22, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did…

  • CVE-2025-24025MedJan 24, 2025
    risk 0.40cvss 6.1epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on the error modal, which leads…

  • CVE-2025-59955MedJan 5, 2026
    risk 0.37cvss 5.7epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members`…

  • CVE-2025-22607MedJan 24, 2025
    risk 0.36cvss 5.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a Coolify instance by…

  • CVE-2025-64422MedJan 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header.…

  • CVE-2026-15507MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the attack is possible. The…

  • CVE-2026-59734HigJul 9, 2026
    risk 0.00cvss 8.8epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_method,…

  • CVE-2026-42201LowJul 7, 2026
    risk 0.00cvss 3.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user,…

  • CVE-2026-34158HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping embedded single quotes. Attackers who can edit application…

  • CVE-2026-42200HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handling did not sufficiently…

  • CVE-2026-42172LowJul 7, 2026
    risk 0.00cvss 3.1epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked token to retain access indefinitely until manually revoked. This issue is fixed in version…

  • CVE-2026-42147MedJul 7, 2026
    risk 0.00cvss 4.9epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side request to the configured endpoint, allowing an…

  • CVE-2026-42145LowJul 7, 2026
    risk 0.00cvss 3.1epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation,…

  • CVE-2026-42143HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping or validation, allowing an…

  • CVE-2026-34198MedJul 7, 2026
    risk 0.00cvss 5.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxies = '*'), accepting X-Forwarded-Host from any source. The TrustHosts middleware, intended to…

  • CVE-2026-34171HigJul 7, 2026
    risk 0.00cvss 8.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can…

  • CVE-2026-34170MedJul 7, 2026
    risk 0.00cvss 4.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GithubApp api_url field is used as the base URL for server-side HTTP requests without allowlisting or private IP blocking, allowing an authenticated…

  • CVE-2026-34168HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument escaping, allowing an authenticated…

  • CVE-2026-34152HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH heredoc transport that preserves newlines, allowing an…

  • CVE-2026-34149LowJul 7, 2026
    risk 0.00cvss 3.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled database credentials and MongoDB collection exclusion names into backup shell commands without adequate…

  • CVE-2026-34058HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Livewire component Server\Resources exposes public methods (startUnmanaged, stopUnmanaged, restartUnmanaged) that accept a container ID parameter…

  • CVE-2026-34057HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the database import Livewire component (app/Livewire/Project/Database/Import.php) allows client-controlled container and server properties to reach shell…

  • CVE-2026-34048CriJul 7, 2026
    risk 0.00cvss 9.9epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect…

  • CVE-2026-34047CriJul 7, 2026
    risk 0.00cvss 9.9epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware, allowing an authenticated user to access terminal functionality…

  • CVE-2026-34044HigJul 7, 2026
    risk 0.00cvss 7.7epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() component looks up resources by UUID without scoping the lookup to the current team, allowing an authenticated user to access logs for…

  • CVE-2026-34037CriJul 7, 2026
    risk 0.00cvss 9.9epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups,…

  • CVE-2026-34035HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands without sufficient encoding, allowing an authenticated user to inject…

  • CVE-2026-34034HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing an authenticated user with access to server Sentinel settings…

  • CVE-2026-42204HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command…

  • CVE-2026-42153HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an…

  • CVE-2026-42148LowJul 6, 2026
    risk 0.00cvss 3.8epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version field without shell…

  • CVE-2026-41899MedJul 6, 2026
    risk 0.00cvss 6.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and no input validation, allowing arbitrary content to be forwarded directly to a Discord…

  • CVE-2026-34599HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege…

  • CVE-2026-34167MedJul 6, 2026
    risk 0.00cvss 5.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor Livewire component exposes a public $activityId property without Livewire's #[Locked] attribute. It loads activities via…

Page 1 of 2