Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available.
Conclusion & alert: CVE-2025-64424 is rated High Exploit Risk (72.4/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.34%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-03 | 0.47% | 0.34% | -0.13% |
| 2 | 2026-05-07 | 0.41% | 0.47% | +0.06% |
| 3 | 2026-03-14 | — | 0.41% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.4 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| coollabs | coolify | < 4.0.0 | cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta100:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta101:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta102:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta103:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta104:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta105:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta106:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta107:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta108:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta109:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta110:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta111:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta112:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta113:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta114:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta115:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta116:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta117:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta118:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta119:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta120:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta121:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta122:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta123:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta124:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta125:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta126:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta127:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta128:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta129:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta130:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta131:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta132:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta133:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta134:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta135:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta136:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta137:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta138:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta139:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta140:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta141:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta142:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta143:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta144:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta145:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta146:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta147:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta148:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta149:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta150:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta151:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta152:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta153:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta154:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta155:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta156:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta157:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta158:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta159:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta160:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta161:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta162:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta163:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta164:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta165:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta166:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta167:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta168:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta169:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta170:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta171:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta172:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta173:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta174:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta175:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta176:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta177:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta178:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://drive.google.com/file/d/1rk7AYxNDkJUwo8uWbzX62PpBxpDYeyrZ/view?usp=drive_link | Exploit |
| https://github.com/coollabsio/coolify/security/advisories/GHSA-qx24-jhwj-8w6x | Exploit Vendor Advisory |