Executive brief
Coolify, an open-source tool for managing servers and databases, was found to have a security flaw in how it handles database health checks. An authenticated user could provide specially crafted database settings (such as a username or database name) to execute unauthorized commands on the underlying database container. This could lead to a full compromise of the database service, including data theft or service disruption.
Technical details
An OS command injection vulnerability exists in Coolify's database health check generation logic. Prior to version 4.0.0-beta.474, the application used shell-form string interpolation for health check commands, incorporating user-controlled fields such as 'postgres_user' and 'postgres_db' without adequate sanitization. An authenticated attacker can inject shell metacharacters (e.g., semicolons, backticks, or pipes) into these fields to execute arbitrary code within the context of the database container. The fix involves migrating from shell-string interpolation to the 'exec-form' (CMD array) for Docker health checks, which treats arguments as discrete elements and bypasses shell parsing.
Affected products
- coollabsio Coolify < 4.0.0-beta.474
Timeline
- 2026-04-20: patched: Fix merged into the repository via PR #9674.
- 2026-04-21: advisory: Version 4.0.0-beta.474 released.
- 2026-07-06: disclosed: CVE-2026-42153 published.