HomeSecurityCoolify: 11 critical security vulnerabilities allow complete server compromise

Coolify: 11 critical security vulnerabilities allow complete server compromise

Cybersecurity researchers have revealed details of critical security vulnerabilities affecting Coolify, an open-source self-hosting platform. The vulnerabilities could lead to authentication bypass and remote code execution.

See also: Vulnerability in Linux battery tool allows changing system settings

Coolify vulnerabilities

Let's look at them in detail:

  • CVE -2025-66209 (CVSS score: 10.0) is a command injection vulnerability in the database backup functionality . It allows any authenticated user, with backup privileges, to execute arbitrary commands on the host server (leading to a container escape and a complete compromise of the server ).
  • CVE -2025-66210 (CVSS score: 10.0) is a command injection vulnerability in the database import functionality and allows attackers to execute arbitrary commands on managed servers , leading to a complete breach of the infrastructure.
  • CVE -2025-66211 (CVSS score: 10.0) is another command injection in PostgreSQL init script management. It allows authenticated users, with database privileges, to execute arbitrary commands as root on the server.
  • CVE -2025-66212 (CVSS score: 10.0) is a command injection vulnerability in the Dynamic Proxy Configuration functionality . It allows users with server administration privileges to execute arbitrary commands as root on managed servers.
  • CVE -2025-66213 (CVSS score: 10.0) is another command injection vulnerability in the File Storage Directory Mount functionality and allows users with application/service administration privileges to execute arbitrary commands as root on managed servers.
  • Next is CVE-2025-64419 (CVSS score: 9.7). A command injection via docker-compose.yaml. It allows attackers to execute arbitrary system commands as root on the Coolify instance.
  • CVE -2025-64420 (CVSS score: 10.0) is an information disclosure vulnerability . Low-privileged users can view the private key of the root user on the Coolify instance. As a result, they can gain unauthorized access to the server via SSH and authenticate as root using the key.
  • CVE -2025-64424 (CVSS score: 9.4) is a command injection. It was discovered in the git source input fields of a resource, allowing a low-privileged user (member) to execute system commands as root on the Coolify instance.
  • CVE -2025-59156 (CVSS score: 9.4) is a command injection in the operating system. It allows a low-privileged user to inject arbitrary Docker Compose instructions and achieve command execution on the underlying host.
  • CVE -2025-59157 (CVSS score: 10.0) is another command injection in the operating system that allows a normal user to enter arbitrary shell commands.
  • Finally, we have CVE-2025-59158 (CVSS score: 9.4). A vulnerability that allows a low-privileged authenticated user to conduct a stored cross-site scripting (XSS) attack during project creation, which is automatically executed in the browser context when an administrator attempts to delete the project or related resource.

See also: Critical n8n vulnerability allows complete control to hackers

Coolify: 11 critical security vulnerabilities allow complete server compromise

Coolify: The versions affected by the above vulnerabilities

  • CVE-2025-66209, CVE-2025-66210, CVE-2025-66211 –
  • CVE-2025-66212, CVE-2025-66213 –
  • CVE-2025-64419 – < 4.0.0-beta.436 (Fix >= 4.0.0-beta.445)
  • CVE-2025-64420, CVE-2025-64424 –
  • CVE-2025-59156, CVE-2025-59157, CVE-2025-59158 –

According to data from the Censys, there are approximately 52,890 exposed Coolify servers as of January 8, 2026, with most located in Germany (15,000), the U.S. (9,800), France (8,000), Brazil (4,200), and Finland (3,400).

See also: CISA: Microsoft Office and HPE OneView vulnerabilities in the KEV Catalog

Although there is no evidence of active exploitation, it is essential that users proceed with the implementation of the fixes as soon as possible.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS