CVE-2025-34159
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-27

Last updated on: 2025-09-19

Assigner: VulnCheck

Description
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project creation. By crafting a malicious service definition that mounts the host root filesystem, an attacker can gain full root access to the underlying server.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-27
Last Modified
2025-09-19
Generated
2026-05-27
AI Q&A
2025-08-27
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 408 associated CPEs
Vendor Product Version / Range
coollabs coolify to 4.0.0 (exc)
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
coollabs coolify 4.0.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects Coolify versions prior to v4.0.0-beta.420.6 and allows authenticated users with low-level member privileges to execute remote code. Specifically, these users can inject arbitrary Docker Compose directives during project creation. By creating a malicious service definition that mounts the host root filesystem, an attacker can gain full root access to the underlying server.


How can this vulnerability impact me? :

The vulnerability can lead to a complete compromise of the server running Coolify. An attacker with low-level privileges can escalate their access to full root access, potentially allowing them to control the server, access sensitive data, modify or delete files, and disrupt services.


What immediate steps should I take to mitigate this vulnerability?

Upgrade Coolify to version 4.0.0-beta.420.6 or later to fix the remote code execution vulnerability. Additionally, restrict authenticated user privileges to prevent low-level members from injecting arbitrary Docker Compose directives during project creation.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart