coolLabs Coolify是coolLabs团队开源的一个开源和自托管的 Heroku/Netlify/Vercel 替代品。 coolLabs coolify 4.0.0-beta.451版本至4.0.0-beta.470版本存在命令注入漏洞,该漏洞源于MongoDB备份处理时未充分验证shell元字符,可能导致拥有高权限的攻击者配置备份输入时注入命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| coollabsio | coolify | >= 4.0.0-beta.451, < 4.0.0-beta.471 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| coollabsio | coolify | >= 4.0.0-beta.451, < 4.0.0-beta.471 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34038 | 9.9 CRITICAL | Coolify authenticated remote command injection leading to RCE and secret exfiltration |
| CVE-2026-42204 | 8.8 HIGH | Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root |
| CVE-2026-42153 | 8.8 HIGH | Coolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in Container |
| CVE-2026-34153 | 8.8 HIGH | Coolify LocalFileVolume fs_path command injection enables RCE |
| CVE-2026-34599 | 8.8 HIGH | Coolify: Authenticated Remote Code Execution in GetLogs Livewire Component |
| CVE-2026-41899 | 6.5 MEDIUM | Coolify unauthenticated feedback endpoint allows Discord webhook abuse |
| CVE-2026-32718 | 6.5 MEDIUM | Coolify read-scoped API tokens can perform state-changing validation operations |
| CVE-2026-34050 | 6.5 MEDIUM | Coolify Settings/Updates Livewire component missing instance administrator authorization |
| CVE-2026-34167 | 5.0 MEDIUM | Coolify: Cross-tenant activity log disclosure via unlocked Livewire property in ActivityMo |
| CVE-2026-42148 | 3.8 LOW | Coolify: Command Injection via Unescaped Version String in Docker Build |
No comments yet