Junglewise Threat Intelligence

CVE-2026-42143: Coollabsio Coolify OS command injection in persistent volume names

CVE-2026-42143 · Severity: high · CVSS 8.8 · Published 2026-07-07

Executive brief

Coolify, an open-source tool for managing servers and databases, contains a vulnerability that allows authenticated users to execute unauthorized commands. By providing a specially crafted name for a storage volume, an attacker can gain full administrative (root) control over the managed servers. This could lead to complete system takeover, data theft, or service disruption across all servers managed by the platform.

Technical details

An OS command injection vulnerability exists in Coolify prior to version 4.0.0-beta.471. The root cause is the lack of escaping or validation when interpolating user-controlled persistent volume names into shell commands (specifically 'docker volume rm') executed via SSH on managed servers. An authenticated attacker with at least 'member' privileges can inject shell metacharacters (e.g., semicolons) into a volume name via the API. When a volume operation—such as deleting a database with the 'Delete Volumes' option—is triggered, the injected commands are executed with root privileges. The issue was addressed by implementing 'escapeshellarg()' for volume names and adding input validation patterns.

Affected products

  • coollabsio Coolify < 4.0.0-beta.471

Timeline

  • 2026-03-26: patched: Fix committed to repository
  • 2026-04-09: advisory: Release v4.0.0-beta.471 published
  • 2026-07-07: disclosed: CVE published to NVD

References