top of page
perceptive_background_267k.jpg

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment va…

Published:

6 juli 2026 om 22:00:00

Alert date:

7 juli 2026 om 05:04:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization, Security Tools

CVE-2026-34035 affects Coolify, an open-source self-hostable server and application management tool. Prior to version 4.0.0-beta.466, log drain secret and environment variable values were interpolated directly into shell commands without proper encoding or sanitization. This flaw allowed authenticated users to inject arbitrary commands that would be executed on the host system. The vulnerability represents a command injection risk with potential for full host compromise by any authenticated user. The issue has been patched in version 4.0.0-beta.466. A fix commit is available on GitHub along with a security advisory. Users of affected versions should upgrade immediately to mitigate the risk of authenticated command injection attacks.

Technical details

Mitigation steps:

Affected products:

Coolify

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page