CVE-2026-34038 is an authenticated remote command injection vulnerability in Coolify, an open-source self-hostable platform for managing servers, applications, and databases. It affects versions prior to 4.0.0-beta.469. The flaw resides in application deployment handling, where user-controlled deployment-related fields, including dockerfile_location and deployment commands, can be abused to inject shell commands. A user with application write permissions can trigger command execution in the deployment context, resulting in remote code execution and exposure of sensitive environment variables through deployment logs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a README and a single Python exploit script. The README documents CVE-2026-34038 in Coolify as an authenticated command injection/RCE issue tied to deployment-related fields, especially dockerfile_location and pre_deployment_command. The exploit script operationalizes this by authenticating to the Coolify REST API with a bearer token, optionally enumerating applications, selecting a target application UUID, patching the application configuration with a shell injection string in dockerfile_location, and also setting pre_deployment_command to the attacker-supplied command. It then starts a deployment, extracts or discovers the resulting deployment UUID, and polls deployment logs to print command output. The default payload is reconnaissance and exfiltration oriented rather than a persistent shell: it prints user and host identity, network interface data, environment variables, and /etc/hosts contents. Structurally, exploit.py has three main functions: get_applications() for target discovery, exploit() for configuration tampering and deployment triggering, and monitor_logs() for status polling and output retrieval. This is a real authenticated RCE exploit, not merely a detector, and its payload is basic but functional, making the repository an operational proof-of-concept.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.