CVE-2026-59734 is a high-severity OS command injection vulnerability in Coolify, an open-source self-hosted platform for managing servers, applications, and databases. Versions prior to 4.0.0-beta.469 are affected. The flaw is in the generate_healthcheck_commands() function in app/Jobs/ApplicationDeploymentJob.php, where the health_check_host, health_check_method, and health_check_path parameters are directly interpolated into shell commands without proper sanitization or neutralization of shell metacharacters. An authenticated attacker can supply crafted health check configuration values that are incorporated into command execution during application deployment, resulting in arbitrary command execution inside the target deployment container.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Bash proof-of-concept exploit script and a detailed README. The script targets CVE-2026-59734, an authenticated OS command injection in Coolify health check configuration. The exploit abuses unsanitized interpolation of health_check_host, health_check_method, and health_check_path into shell commands used during deployment health checks. Structure: README.md documents the vulnerability, affected/fixed versions, usage examples, and expected behavior. coolify_healthcheck_rce_poc.sh is the operational entry point. It implements two modes: a safe offline local validation mode that reproduces the vulnerable command-building pattern and demonstrates injection through all three parameters, and a remote exploitation mode that interacts with a real Coolify instance over its API. Capabilities: In remote mode, the script validates dependencies, accepts a target URL, bearer token, and application UUID, then updates the target application's health check configuration with an injected payload, verifies the payload was stored unsanitized, and triggers deployment so the command executes inside the container. It supports a default proof-of-execution payload, custom payloads, and an optional reverse shell using attacker-supplied host/port. It also supports cleanup by restoring the original health check configuration after exploitation. Targeting: The exploit is intended for vulnerable Coolify versions up to v4.0.0-beta.460; the README states the issue is fixed in v4.0.0-beta.469. Attack precondition is authenticated API access to a target application. Overall, this is a real exploit PoC with practical remote RCE functionality rather than a mere detector.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.