Junglewise Threat Intelligence

CVE-2026-34049: Coolify OS command injection in MongoDB backup handling

CVE-2026-34049 · Severity: low · CVSS 3.3 · Published 2026-07-06

Technologies: Coollabs Coolify. Vendors: Coollabs.

Executive brief

Coolify is an open-source platform used to manage and self-host servers, applications, and databases. A security flaw was found in how the tool handles MongoDB database backups, where it failed to properly check for malicious characters in collection names. If exploited by a highly privileged user, this could allow them to execute unauthorized commands on the underlying system, potentially compromising the server's integrity or accessing sensitive data.

Technical details

An OS command injection vulnerability exists in Coolify versions 4.0.0-beta.451 through 4.0.0-beta.470 due to improper neutralization of special elements in MongoDB collection names during backup operations. The root cause is a failure to validate shell metacharacters in the 'databases_to_backup' input before interpolating them into shell commands within the DatabaseBackupJob. An attacker with high privileges (sufficient to configure database backup settings) can inject arbitrary commands via the API or web UI. The vulnerability is mitigated by the requirement for high privileges and a high attack complexity. The issue was addressed in version 4.0.0-beta.471 by implementing the validateDatabasesBackupInput() helper and using proper shell escaping.

Affected products

  • coollabsio Coolify 4.0.0-beta.451 through 4.0.0-beta.470

Timeline

  • 2026-03-25: patched: Fix committed to repository
  • 2026-04-09: advisory: Release v4.0.0-beta.471 published
  • 2026-07-06: disclosed: CVE published to NVD

References

Related threats