Coolify是coolLabs开源的一个开源和自托管的 Heroku/Netlify/Vercel 替代品。 Coolify v4.0.0-beta.420.7之前版本存在安全漏洞,该漏洞源于项目部署工作流中存在远程代码执行,可能导致完全控制服务器。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| coolLabs Technologies | Coolify | < 4.0.0-beta.420.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| coolLabs Technologies | Coolify | 0 ~ 4.0.0-beta.420.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Authenticated low-privileged RCE in Coolify via unsanitized shell commands in the Git Repository field. | https://github.com/Eyodav/CVE-2025-34161 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-34159 | Coolify Docker Compose Directive Injection in Application Deployment Workflow | |
| CVE-2025-34157 | Coolify Stored Cross-Site Scripting (XSS) in Project Name Field |
No comments yet