- Colify has command injection vulnerability in project git source CVE-2025-64424

- Colify has command injection vulnerability in project git source CVE-2025-64424

CVE ID : CVE-2025-64424 Published : Jan. 5, 2026, 8:45 p.m. | 27 minutes ago Description : Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
LOW
Published
Jan. 5, 2026
Impact: command injection

Source: Telegram CVE Monitor