Coolify disclosed and patched CVE-2026-59734, a high-severity OS command injection flaw that allows an authenticated remote attacker to achieve remote code execution inside deployment containers. The vulnerability affects versions prior to 4.0.0-beta.469 and stems from unsafe interpolation of user-controlled health_check_host, health_check_method, and health_check_path values in generate_healthcheck_commands() within app/Jobs/ApplicationDeploymentJob.php. The issue carries a CVSS v3.1 score of 8.8.
The fix landed in Coolify via commit 0ffcee7a4dcd24f92b5fab8c9c7be140b9532733, which adds runtime validation for user-supplied CMD health check commands with a restrictive regular expression and maximum length checks, corrects shell escaping for HTTP health check methods in generated curl commands, and falls back to HTTP health checks when validation fails. The patch also introduced HealthCheckCommandInjectionTest.php, and the vendor linked the remediation to its release, pull request, patch commit, and GitHub security advisory.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-59734 was disclosed as a high-severity OS command injection vulnerability affecting Coolify versions prior to 4.0.0-beta.469. The issue allows an authenticated remote attacker to achieve code execution inside deployment containers via unsafe interpolation in health check configuration handling.
A GitHub commit in the coollabsio/coolify repository introduced validation for user-supplied CMD health check commands, corrected shell escaping in generated curl commands, and added a security-focused unit test to prevent OS command injection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.