Junglewise Threat Intelligence

CVE-2026-34597: Coolabsio Coolify OS command injection in Nixpacks build pack

CVE-2026-34597 · Severity: high · CVSS 8.8 · Published 2026-06-29

Technologies: Coollabs Coolify. Vendors: Coollabs.

Executive brief

Coolify is an open-source platform used to manage and deploy servers, applications, and databases. A security vulnerability allows an authenticated user to execute malicious commands on the underlying server by providing specially crafted build parameters. This could lead to a complete takeover of the host system, resulting in data theft, service disruption, or unauthorized access to other managed resources.

Technical details

An OS command injection vulnerability (CWE-78) exists in Coolify's Nixpacks build pack handling within 'app/Jobs/ApplicationDeploymentJob.php'. The 'nixpacks_build_cmd' function fails to sanitize the 'install_command' parameter, instead wrapping it in double quotes and concatenating it into a shell command string. This string is subsequently passed to 'executeInDocker()', which executes it via 'bash -c'. An authenticated attacker with project management permissions can inject shell metacharacters (e.g., ';') into the 'Install Command' field to break out of the quoted string and execute arbitrary commands on the deployment host with the privileges of the Coolify process. The issue is resolved in version 4.0.0-beta.470 by implementing proper argument escaping using 'escapeshellarg()'.

Affected products

  • coollabsio Coolify < 4.0.0-beta.470

Timeline

  • 2026-06-25: advisory: GitHub Security Advisory published by vendor
  • 2026-06-29: disclosed: CVE published to NVD
  • 2026-06-29: patched: Fix released in version 4.0.0-beta.470

References

Related threats