Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 10epss 3.8%
from disclosure to weapon0 days
Published on NVDDec 23
1st PoCDec 23
exploitation probability
3.8%top 11% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in backup operations are passed directly to shell commands without sanitization, enabling full remote code execution. Version 4.0.0-beta.451 fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
coollabsio · coolifypublic PoCs found — 1
githubgithub.com/0xrakan/coolify-cve-2025-66209-66213★ 1⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.