VendorscoolLabscoolifyall versions
Vulnerabilities

coolLabs Coolify

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2025-22609
Coolify Vulnerable to Private Key Hijacking / Remote Command Execution (RCE)
Published 2025-01-24 · Analyzed
10.0EPSS 0.008
CVE-2025-22612
Coolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE)
Published 2025-01-24 · Analyzed
10.0EPSS 0.006
CVE-2025-66209
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup
Published 2025-12-23 · Modified
9.9EPSS 0.039
CVE-2025-59157
Coolify has Git Repository RCE
Published 2026-01-05 · Analyzed
9.9EPSS 0.018
CVE-2025-64420
Coolify members can see private key of root user
Published 2026-01-05 · Analyzed
9.9EPSS 0.005
CVE-2025-22611
Coolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE)
Published 2025-01-24 · Analyzed
9.9EPSS 0.005
CVE-2025-64419
Coolify vulnerable to command injection via docker-compose.yaml parameters
Published 2026-01-05 · Analyzed
9.6EPSS 0.006
CVE-2025-66213
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Directory Mount Path
Published 2025-12-23 · Modified
9.4EPSS 0.031
CVE-2025-66212
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Configuration Filename
Published 2025-12-23 · Modified
9.4EPSS 0.031
CVE-2025-34161
Coolify Git Repository Field Command Injection in Project Deployment Workflow
Published 2025-08-27 · Analyzed
9.4EPSS 0.030
CVE-2025-66211
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script Filename
Published 2025-12-23 · Modified
9.4EPSS 0.027
CVE-2025-66210
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Import
Published 2025-12-23 · Modified
9.4EPSS 0.027
CVE-2025-64424
Colify has command injection vulnerability in project git source
Published 2026-01-05 · Analyzed
9.4EPSS 0.021
CVE-2025-59156
Coolify has Docker Compose Injection issue
Published 2026-01-05 · Analyzed
9.4EPSS 0.010
CVE-2025-34159
Coolify Docker Compose Directive Injection in Application Deployment Workflow
Published 2025-08-27 · Analyzed
9.4EPSS 0.010
CVE-2025-59158
Coolify has Stored XSS in Project Name
Published 2026-01-05 · Analyzed
9.4EPSS 0.005
CVE-2025-34157
Coolify Stored Cross-Site Scripting (XSS) in Project Name Field
Published 2025-08-27 · Analyzed
9.4EPSS 0.005
CVE-2025-64423
Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links
Published 2026-01-05 · Analyzed
8.8EPSS 0.003
CVE-2025-64421
Coolify has a privilege escalation - low privileged user can invite themselves as an admin user
Published 2026-01-05 · Analyzed
8.7EPSS 0.003
CVE-2025-22605
Coolify OS Command Injection Vulnerability in SSH Command Generation
Published 2025-01-24 · Analyzed
8.5EPSS 0.005
CVE-2025-64425
Coolify has host header injection in forgot password
Published 2026-01-05 · Analyzed
8.5EPSS 0.004
CVE-2025-22606
Coolify Command Injection Vulnerability in Project Name
Published 2025-01-24 · Analyzed
8.5EPSS 0.003
CVE-2025-22610
Coolify Vulnerable to OAuth Secrets Leak
Published 2025-01-24 · Analyzed
6.5EPSS 0.004
CVE-2025-22608
Coolify Vulnerable to Revocation of Arbitrary Team Invitations (DOS)
Published 2025-01-24 · Analyzed
6.5EPSS 0.004
CVE-2025-24025
Coolify Vulnerable to Reflected XSS on Tag Search
Published 2025-01-24 · Analyzed
6.1EPSS 0.002
CVE-2025-59955
Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint
Published 2026-01-05 · Analyzed
5.7EPSS 0.003
CVE-2025-64422
Rate-limit bypass on login via X-Forwarded-Host header
Published 2026-01-05 · Analyzed
5.5EPSS 0.003
CVE-2025-22607
Coolify Vulnerable to GitHub / GitLab OAuth Secrets Leak
Published 2025-01-24 · Analyzed
5.5EPSS 0.002