CVE-2025-34159
HIGHCoollabs Coolify < 4.0.0 - Code Injection
Title source: ruleDescription
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project creation. By crafting a malicious service definition that mounts the host root filesystem, an attacker can gain full root access to the underlying server.
Exploits (1)
Scores
CVSS v3
8.8
EPSS
0.0057
EPSS Percentile
68.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
CWE-20
Status
published
Products (1)
coollabs/coolify
4.0.0 beta100 (50 CPE variants)
Published
Aug 27, 2025
Tracked Since
Feb 18, 2026