coolLabs Coolify是coolLabs团队开源的一个开源和自托管的 Heroku/Netlify/Vercel 替代品。 CoolLabs Coolify 4.0.0-beta.464之前版本存在命令注入漏洞,该漏洞源于executeInDocker()助手在bash -c '{$command}'中未转义单引号,用户控制的docker_compose_custom_build_command和docker_compose_custom_start_command字段直接插值,可能导致单引号跳
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.464 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.464 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27957 | 8.8 HIGH | Coolify: Authenticated RCE via command injection in CA certificate management feature |
| CVE-2026-27883 | 5.0 MEDIUM | Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure |
| CVE-2026-27881 | 5.0 MEDIUM | Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} ( |
| CVE-2026-27882 | 4.8 MEDIUM | Coolify: Timing Attack in GitLab Webhook Token Validation |
| CVE-2026-27956 | 4.3 MEDIUM | Coolify: Cross-team application domain enumeration via domains_by_server endpoint |
No comments yet