CVE-2025-64424 is a command injection vulnerability in the Git source input fields of Coolify resources. Coolify versions through v4.0.0-beta.434 allow a low-privileged member to inject system commands that execute as root on the Coolify instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: a containerized training/CTF lab for exploiting a Coolify Git repository URL command-injection leading to RCE (claimed as CVE-2025-64424 / GHSA-qx24-jhwj-8w6x; walkthrough text also inconsistently mentions CVE-2025-66202). Core exploit capability: - Command injection via the Coolify “Repository URL” field. User-controlled repository URL is concatenated into a `git ls-remote` command and executed through a wrapper that ultimately runs `docker exec <id> bash -c '<command>'`. Shell metacharacters (e.g., `;`, `#`, `$IFS`) allow arbitrary command execution in the container context. - Demonstrated payload reads `/flag/flag.txt` (e.g., `https://gitlab.com/fake/repo.git;cat$IFS/flag/flag.txt#`). Another script variant writes to `/tmp/flag_out.txt`. Repository structure: - Walkthrough documentation (Walkthrough/*.md): - Technical_Breakdown.md explains the vulnerable sink (ApplicationDeploymentJob.php building `git ls-remote` with raw URL) and the execution wrapper (executeInDocker using `bash -c`), plus remediation guidance. - solution.md and step-by-step.md provide UI-driven exploitation steps and example payloads. - management.md provides docker compose lifecycle commands. - Lab environment (lab/*): - Dockerfile pins Coolify image to 4.0.0-beta.420.6 and modifies ApplicationDeploymentJob.php to mount a local `lab/flag` directory into `/flag:ro` inside the Coolify container. - Dockerfile.helper builds a helper image that contains `/flag/flag.txt`. - docker-compose.yml orchestrates Coolify + postgres + redis + soketi and a `coolify-host` alpine container providing SSH and mounting `/flag` and `/var/run/docker.sock`. - verify_exploit.py: Playwright automation that registers an admin user, navigates the UI, and injects a repository URL containing shell commands to trigger the RCE. - dump_html.py: Playwright utility to fetch and dump the Coolify page HTML. - install.sh/setup_ssh.sh/start-with-ssh.sh: supporting scripts for installation/SSH setup. Notable observations: - The lab is designed for local use (http://localhost:10005). It includes high-impact mounts (docker.sock) typical for Coolify; in real deployments, successful RCE could potentially be escalated to host-level control via Docker socket access. - The automated exploit in verify_exploit.py uses a payload with literal spaces (`; cat /flag/...`) which may conflict with the walkthrough’s emphasis on bypassing space validation using `$IFS`; however, the lab’s UI/validation behavior may differ or the script may be a best-effort driver rather than a guaranteed bypass.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical command injection vulnerability in unspecified Git-related user input fields in Coolify, allowing low-privileged attackers to execute arbitrary system commands as root.
A command injection vulnerability in Coolify's git source input fields allowing low-privileged users to execute system commands as root.
A command injection vulnerability in Coolify (up to and including v4.0.0-beta.434) allows low privileged users to execute system commands as root via the git source input fields.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.