top of page
perceptive_background_267k.jpg

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command gene…

Published:

5 juli 2026 om 22:00:00

Alert date:

6 juli 2026 om 23:01:31

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Cloud & Virtualization

CVE-2026-42153 is a command injection vulnerability in Coolify, an open-source self-hostable server and application management tool. Prior to version 4.0.0-beta.474, the PostgreSQL healthcheck command generation incorporated attacker-controlled database settings (postgres_user and postgres_db) directly into shell-form commands without proper sanitization. An authenticated user could exploit this flaw to inject arbitrary commands that would be executed within the database container. The vulnerability stems from improper handling of user-supplied input in shell command construction. The issue has been patched in version 4.0.0-beta.474. A corresponding GitHub pull request, commit, and security advisory have been published detailing the fix. The vulnerability requires authentication, limiting the attack surface but still posing significant risk in multi-tenant or shared deployments. Users are advised to upgrade immediately to the patched version.

Technical details

Mitigation steps:

Affected products:

Coolify (prior to 4.0.0-beta.474)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page