Junglewise Threat Intelligence

CVE-2026-42153: coollabsio Coolify OS command injection in PostgreSQL healthcheck

CVE-2026-42153 · Severity: high · CVSS 8.8 · Published 2026-07-06

Technologies: Coollabs Coolify. Vendors: Coollabs.

Executive brief

Coolify, an open-source tool for managing servers and databases, was found to have a security flaw in how it handles database health checks. An authenticated user could provide specially crafted database settings (such as a username or database name) to execute unauthorized commands on the underlying database container. This could lead to a full compromise of the database service, including data theft or service disruption.

Technical details

An OS command injection vulnerability exists in Coolify's database health check generation logic. Prior to version 4.0.0-beta.474, the application used shell-form string interpolation for health check commands, incorporating user-controlled fields such as 'postgres_user' and 'postgres_db' without adequate sanitization. An authenticated attacker can inject shell metacharacters (e.g., semicolons, backticks, or pipes) into these fields to execute arbitrary code within the context of the database container. The fix involves migrating from shell-string interpolation to the 'exec-form' (CMD array) for Docker health checks, which treats arguments as discrete elements and bypasses shell parsing.

Affected products

  • coollabsio Coolify < 4.0.0-beta.474

Timeline

  • 2026-04-20: patched: Fix merged into the repository via PR #9674.
  • 2026-04-21: advisory: Version 4.0.0-beta.474 released.
  • 2026-07-06: disclosed: CVE-2026-42153 published.

References

Related threats