NVD disclosure day

Published threat advisories for August 27, 2025

CVE advisoryCRITICAL

CVE-2025-34163

Dongsheng Logistics Software allows attackers to take full control of your systems by uploading malicious files.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An external attacker could run malicious code on servers running Dongsheng Logistics Software by uploading a crafted file. This could allow them to gain control of the system, potentially impacting sensitive logistics data and operations.

CVE advisoryCRITICAL

CVE-2025-34161

Coolify Project Deployment Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Coolify, a platform for managing application deployments, has a critical vulnerability enabling authenticated users with low-level privileges to execute arbitrary shell commands via the Git Repository field during project creation, potentially leading to full server compromise.

CVE advisoryCRITICAL

CVE-2025-34159

Coolify Remote Code Execution via Malicious Docker Directives

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Coolify versions prior to v4.0.0-beta.420.6 have a critical remote code execution vulnerability. Authenticated users with low-level privileges can inject malicious Docker Compose directives during project creation, potentially leading to full root access on the underlying server by mounting the host's filesystem. This

CVE advisoryCRITICAL

CVE-2025-34157

Coolify Stored Cross-Site Scripting Leads to Instance Compromise

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Coolify, enabling low-privilege users to execute malicious scripts via crafted project names. This stored cross-site scripting flaw, when triggered by an administrator action, can lead to a full Coolify instance compromise, including the theft of sensitive data and access to managed s