Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-34597: Coolify: Authenticated Remote Code Execution via User Input
CVE-2026-34597
Summary
A security issue was found in Coolify's way of handling user input. This could allow an attacker with valid access to run malicious code on the server. Update to the latest version of Coolify to fix this issue.
Original title
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.470, a critical Authenticated Host Remote Code Execution (RCE) vulnerability ...
Original description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.470, a critical Authenticated Host Remote Code Execution (RCE) vulnerability was discovered in Coolify. The flaw resides in the handling of user-defined build parameters for the Nixpacks build pack. Specifically, the install_command provided by a user is directly concatenated into a shell command string that is executed on the deployment host during the building phase. An attacker can leverage this to escape the intended build context and execute arbitrary commands with host-level privileges. This vulnerability is fixed in 4.0.0-beta.470.
nvd CVSS3.1
8.8
Vulnerability type
CWE-78
OS Command Injection
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 29 Jun 2026