Executive brief
Coolify is an open-source platform used to manage and deploy applications, databases, and servers. A security flaw allows authenticated users to execute unauthorized commands on the remote servers managed by the platform. This could lead to a complete takeover of the managed infrastructure, data theft, or service disruption.
Technical details
An OS command injection vulnerability exists in Coolify's Livewire component 'Server\Resources'. The 'startUnmanaged', 'stopUnmanaged', and 'restartUnmanaged' methods accept a '$id' parameter from the browser and interpolate it directly into shell commands (e.g., 'docker stop -t 0 $id') executed via SSH on managed servers. Because the input lacks sanitization or shell escaping (such as escapeshellarg), an authenticated attacker can use command separators to execute arbitrary code with the privileges of the SSH user on the target server. The vulnerability is fixed in version 4.0.0-beta.471 by adding input validation patterns and proper shell argument escaping.
Affected products
- coollabsio Coolify < 4.0.0-beta.471
Timeline
- 2026-03-25: patched: Fix merged into codebase
- 2026-04-09: advisory: Release v4.0.0-beta.471 published
- 2026-07-02: disclosed: Security advisory published
- 2026-07-07: other: CVE published to NVD