Executive brief
Coolify, an open-source self-hosted platform for managing servers and applications, is vulnerable to a security flaw in how it handles Docker image names. An attacker with basic user access can provide a specially crafted image name containing malicious commands. If successful, this allows the attacker to execute arbitrary code on the underlying server, potentially leading to a full system takeover or data theft.
Technical details
An OS command injection vulnerability exists in Coolify 4.0.0 within the Image Name Handler component. The application fails to properly sanitize Docker image reference fields before incorporating them into shell commands used for deployment (e.g., 'docker pull'). By injecting shell metacharacters (such as semicolons) into the image name field, a remote authenticated attacker with low privileges can execute arbitrary commands on the host operating system. While the vendor did not officially respond to the initial disclosure, version 4.1.2 reportedly includes improved input validation for image and branch fields.
Affected products
- coollabsio Coolify 4.0.0
Timeline
- 2026-06-22: advisory: NVD publication date
- 2026-05-15: other: Vulnerability verification via PoC recorded