Security Advisory

CVE-2025-64424

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-05 20:45:09
Last updated 2026-01-05 21:48:42
Assigner GitHub_M
State PUBLISHED

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available.