External risk intelligence

Coolify Application Deployment Remote Code Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-59156

Coolify is a self-hosted platform for managing applications and infrastructure. Such management consoles are typically deployed as centralized web-based interfaces, often accessible over a network to facilitate remote administration and deployment workflows, making them a common target for internet-facing service exposure.

OS Command Injection

Coollabs Coolify

before 4.0.04.0.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Coolify, a server management tool, allows a low-privileged user to execute arbitrary commands on the host operating system by injecting malicious configurations during application deployment. This bypasses container isolation and can grant attackers root-level access.

  • Allows code execution on host systems.
  • Critical vulnerability could impact system integrity.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low-level access to Coolify can inject malicious code during application deployment. This allows them to modify Docker Compose configurations to mount the host's filesystem, enabling them to execute commands with root privileges on the underlying operating system and bypass container security.

  • Network access, low-privileged user.
  • Injecting malicious Docker Compose directives.
  • Root-level command execution on host.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged member could inject malicious Docker Compose directives during project creation or updates in Coolify. This could allow them to define a service that mounts the host's filesystem, potentially leading to root-level command execution on the host operating system and bypassing container isolation.

  • Host OS and containerized services at risk.
  • Attacker mounts host filesystem via malicious service.
  • Root command execution, container escape possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Coolify application owner or the infrastructure team managing the self-hosted environment is likely responsible for addressing this vulnerability. The first practical step is to identify all instances of Coolify, confirm their network exposure and business criticality, and then coordinate remediation with the accountable owner.

  • Application or infrastructure teams own the issue.
  • Verify Coolify instances and their exposure.
  • Plan and execute the upgrade to patched version.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Coolify?

Coolify is an open-source, self-hosted platform designed to streamline server management and application deployment. Developers use it to easily manage their infrastructure, databases, and containerized applications from a single, centralized web-based dashboard.

What does this CVE-2025-59156 vulnerability mean?

This is a Remote Code Execution vulnerability classified as CWE-78 (OS Command Injection). It allows a user with low-level permissions to trick the system into running unauthorized commands on the underlying host operating system by injecting malicious configuration settings during the application deployment process.

How can an attacker trigger this bug?

An attacker triggers this by manipulating Docker Compose directives while creating or updating a project. By defining a service that mounts the host's filesystem, they can bypass container isolation and gain full control. It cannot be triggered by users without at least low-level access to the Coolify management interface.

Is my Coolify instance at high risk?

Per Halo Surface Signal, because Coolify acts as a centralized administration console, it is frequently deployed with network accessibility to support remote workflows. Any instance reachable over a network, especially if internet-facing, should be considered a potential target for this flaw.

What should I do to secure my Coolify setup?

Your first step is to verify the version of Coolify you are running. If you are using any version prior to 4.0.0-beta.420.7, you must prioritize upgrading to that version or higher, which contains the official patch for this security issue.

References