← Volver a CVEs
CVE-2025-66209
CRITICAL9.9
Descripcion
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in backup operations are passed directly to shell commands without sanitization, enabling full remote code execution. Version 4.0.0-beta.451 fixes the issue.
Detalles CVE
Puntuacion CVSS v3.19.9
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado12/23/2025
Ultima modificacion3/17/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
coollabs:coolify
Debilidades (CWE)
CWE-78
Referencias
https://github.com/0xrakan/coolify-cve-2025-66209-66213(security-advisories@github.com)
https://github.com/coollabsio/coolify/pull/7375(security-advisories@github.com)
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.451(security-advisories@github.com)
https://github.com/coollabsio/coolify/security/advisories/GHSA-vm5p-43qh-7pmq(security-advisories@github.com)
https://github.com/coollabsio/coolify/security/advisories/GHSA-vm5p-43qh-7pmq(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.