Sploitus

CVE-2025-34161

2 known exploits for CVE-2025-34161

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.

Affected products
Coolify
Coollabs Coolify
< 4.0.0
Fix
Available
CVSS 4.0
9.4 CRITICAL
CVSS 3.1
8.8 HIGH
EPSS
2.9% (86th percentile)
Weakness
CWE-78, CWE-20
NVD status
Analyzed
Published
2025-08-27
Attack patterns
CAPEC-88

Fix

"feat(ACL): (Not activated yet) Members from now on should not able to change stuffs around Coolify. They can only view things as it should be from day 1."

CVE-2025-34161 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2025-34161

Proof-of-concept code and exploit modules indexed by Sploitus