Junglewise Threat Intelligence

CVE-2026-34035: coollabsio Coolify command injection in Log Drain configuration

CVE-2026-34035 · Severity: high · CVSS 8.8 · Published 2026-07-07

Executive brief

Coolify is an open-source platform used to manage and host servers, applications, and databases. A security flaw in the log management component allows an authorized user to execute malicious commands on the underlying server. This could lead to a complete takeover of the hosting infrastructure, unauthorized access to sensitive data, and disruption of all hosted services.

Technical details

An OS command injection vulnerability (CWE-78) exists in Coolify's log drain configuration logic within 'app/Actions/Server/StartLogDrain.php' and 'app/Livewire/Server/LogDrains.php'. The application constructs shell commands by interpolating user-provided log drain secrets (such as Axiom API keys) directly into unquoted 'echo' commands. An authenticated attacker with access to server settings can provide a crafted payload containing shell metacharacters (e.g., '$(id)') to achieve Remote Code Execution (RCE) on the host server. The issue has been addressed in version 4.0.0-beta.466 by implementing base64 encoding for environment variables and adding regex validation for input fields.

Affected products

  • coollabsio Coolify < 4.0.0-beta.466

Timeline

  • 2026-03-04: disclosed: Vulnerability discovered by Xyptonize
  • 2026-03-11: patched: Fixed in version 4.0.0-beta.466
  • 2026-07-07: advisory: CVE-2026-34035 published

References