Security researchers have identified and disclosed a series of critical vulnerabilities in Coolify, an open-source self-hosting platform used for managing servers, applications, and databases. The flaws, affecting versions up to and including v4.0.0-beta.434, include multiple command injection vulnerabilities (such as CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, CVE-2025-66213, CVE-2025-64419, CVE-2025-64424, CVE-2025-59156, and CVE-2025-59157) that allow authenticated users with varying levels of privilege to execute arbitrary commands as root on the host server. Additional issues include a privilege escalation flaw (CVE-2025-64421) enabling low-privileged users to grant themselves admin access, an information disclosure vulnerability (CVE-2025-64420) exposing the root user's private SSH key, a host header injection in the password reset workflow (CVE-2025-64425), and a stored XSS vulnerability (CVE-2025-59158) in project names. Several of these vulnerabilities have CVSS scores of 9.4 or higher, indicating critical risk, and many allow for remote exploitation by authenticated users.
Exploitation of these vulnerabilities could result in full server compromise, unauthorized root access, account takeover, and execution of arbitrary code on affected Coolify instances. Some vulnerabilities have been patched in later beta versions (e.g., 4.0.0-beta.420.7 and 4.0.0-beta.445), but for others, it is unclear if a fix is available at the time of disclosure. Organizations using self-hosted Coolify should urgently review their deployments, apply available patches, and audit user permissions to mitigate the risk of exploitation. The breadth and severity of these flaws highlight the importance of prompt vulnerability management and monitoring for unauthorized activity on Coolify-managed infrastructure.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Coolify fixed CVE-2026-34594 in version 4.0.0-beta.471, addressing an authenticated command injection flaw in Destination Network Management. The issue affected versions prior to 4.0.0-beta.471 and could let users with destination management permissions execute arbitrary commands as root on managed servers.
Coolify fixed CVE-2026-34597 in version 4.0.0-beta.470, addressing an authenticated host remote code execution flaw caused by unsafe handling of user-defined Nixpacks build parameters. The issue affected versions prior to 4.0.0-beta.470 and could let authenticated attackers execute arbitrary commands with host-level privileges during the build phase.
A GitHub advisory disclosed an authenticated command injection vulnerability in Coolify's CA Certificate management feature affecting versions through 4.0.0-beta.463. The flaw could let any authenticated user associated with a managed server execute arbitrary commands as the configured SSH user on the managed host, and it was patched in version 4.0.0-beta.464.
The Hacker News reported that Coolify had disclosed 11 critical vulnerabilities enabling full server compromise on self-hosted instances, including authentication bypass, remote code execution, and information disclosure issues across multiple components. The report said more than 52,000 Coolify hosts were exposed globally and noted no evidence of active exploitation at the time.
Coolify fixed CVE-2025-64419 in version 4.0.0-beta.445, addressing improper sanitization of docker-compose.yaml parameters that could let attackers execute arbitrary commands as root when users built applications from malicious repositories. Users were advised to update and avoid untrusted repositories.
On January 5, 2026, security-advisories@github.com disclosed several additional Coolify vulnerabilities, including exposure of the root user's private key (CVE-2025-64420), privilege escalation through self-invitation as admin (CVE-2025-64421), command injection via docker-compose.yaml parameters fixed in 4.0.0-beta.445 (CVE-2025-64419), command injection in project git source fields (CVE-2025-64424), and host header injection in password reset flows (CVE-2025-64425). Some advisories noted public proof-of-concept material and unclear patch status for several issues.
Coolify released version 4.0.0-beta.420.7 to fix three critical vulnerabilities affecting earlier versions: command injection via the Git Repository field (CVE-2025-59157), Docker Compose injection leading to root command execution (CVE-2025-59156), and a stored XSS issue in project names (CVE-2025-59158). These flaws allowed low-privileged users to achieve remote code execution or target administrators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
13 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.