Executive brief
Coolify is an open-source platform used to manage and host servers, applications, and databases. A security flaw in the log management component allows an authorized user to execute malicious commands on the underlying server. This could lead to a complete takeover of the hosting infrastructure, unauthorized access to sensitive data, and disruption of all hosted services.
Technical details
An OS command injection vulnerability (CWE-78) exists in Coolify's log drain configuration logic within 'app/Actions/Server/StartLogDrain.php' and 'app/Livewire/Server/LogDrains.php'. The application constructs shell commands by interpolating user-provided log drain secrets (such as Axiom API keys) directly into unquoted 'echo' commands. An authenticated attacker with access to server settings can provide a crafted payload containing shell metacharacters (e.g., '$(id)') to achieve Remote Code Execution (RCE) on the host server. The issue has been addressed in version 4.0.0-beta.466 by implementing base64 encoding for environment variables and adding regex validation for input fields.
Affected products
- coollabsio Coolify < 4.0.0-beta.466
Timeline
- 2026-03-04: disclosed: Vulnerability discovered by Xyptonize
- 2026-03-11: patched: Fixed in version 4.0.0-beta.466
- 2026-07-07: advisory: CVE-2026-34035 published