External risk intelligence

Coolify Command Injection Vulnerability Allows Root Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-64424

Coolify is a management platform for servers and applications. While often self-hosted, it is designed as an internet-accessible web-based management interface for DevOps teams and developers, making it a commonly exposed administrative surface in environments where it is deployed.

Command Injection

Coollabs Coolify

before 4.0.04.0.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Coolify, a tool for managing servers and applications, could allow unauthorized command execution. This means a user with limited access could potentially run commands on the system as an administrator. The primary concern is to confirm if this tool is in use and if it is affected.

  • Low-privilege users could run commands as root.
  • Confirms relevance and exposure for leadership.
  • Assess impact and ensure system integrity.

Attack Path

How an attacker could exploit the issue

An attacker with low-privileged access to Coolify can exploit a command injection flaw within the git source input fields. This allows them to execute arbitrary system commands as the root user on the server hosting Coolify, leading to a complete compromise of the instance. It is currently unclear if a patch has been released for this vulnerability.

  • Low privileged access is required.
  • Git source input fields are the trigger.
  • Full system compromise is the risk.

Live Threat

Current exploitation, exposure, and threat context

A command injection vulnerability in Coolify could allow a low-privileged user to execute arbitrary system commands as root on the Coolify instance. This could affect the integrity and availability of the server hosting Coolify, as well as any applications, servers, or databases managed by it.

  • System commands could be executed.
  • Via git source input fields.
  • Compromise of the Coolify instance.

Operational Fix

Recommended remediation, mitigation, and detection steps

The command injection vulnerability in Coolify affects the git source input fields and allows low-privileged users to execute arbitrary commands as root. This impacts users with self-hosted instances of Coolify, potentially exposing the entire Coolify instance and its managed resources. The first practical step is to identify all Coolify instances, confirm their reachability and criticality, and locate the responsible owner for remediation.

  • Determine ownership: Application or platform teams.
  • Verify: Identify and confirm reachability and criticality.
  • Action: Plan remediation or implement controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Coolify?

Coolify is an open-source, self-hosted platform that simplifies the management of servers, applications, and databases. Developers and DevOps teams use it as a centralized dashboard to deploy and monitor their technical infrastructure.

What does CVE-2025-64424 mean?

This is a command injection vulnerability, classified as CWE-77. It occurs when an application improperly filters input before executing system commands. In this case, it allows a low-privileged user to force the server to run unauthorized commands with root-level permissions.

How is this vulnerability triggered?

An attacker triggers the flaw by injecting malicious input into the git source fields within the Coolify interface. It is important to note that this requires an existing, low-privileged user account; it cannot be triggered by someone without any access to the system.

Is my Coolify instance at risk?

According to Halo Surface Signal, Coolify is designed as an internet-accessible management tool, which often places it on an exposed administrative surface. If your instance is reachable from the internet, the risk is higher, as an attacker with low-level access could gain full control.

What should I do if I run Coolify?

First, locate all running instances of Coolify within your environment and identify the teams responsible for them. Once identified, verify their network reachability to determine exposure levels and monitor for any official updates or patches from the maintainers.

References