Aller au contenu

Fiche vulnérabilité

CVE-2025-34161 : faille élevée coollabs coolify (CVSS 8.8)

Description

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
27 août 2025
Dernière mise à jour
14 juil. 2026

Produits concernés

  • coollabs coolify

Références

Rechercher une autre vulnérabilité dans la base CVE