CVE-2025-34161
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.
- Affected products
- Coolify
- Coollabs Coolify
- < 4.0.0
- Fix
- Available
- CVSS 4.0
- 9.4 CRITICAL
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 2.9% (86th percentile)
- Weakness
- CWE-78, CWE-20
- NVD status
- Analyzed
- Published
- 2025-08-27
- Attack patterns
- CAPEC-88
Fix
"feat(ACL): (Not activated yet) Members from now on should not able to change stuffs around Coolify. They can only view things as it should be from day 1."
CVE-2025-34161 at NVD
2 known exploits for CVE-2025-34161
Proof-of-concept code and exploit modules indexed by Sploitus