← Back

CVE-2025-22605

nvd nist
Published: Jan 24, 2025Modified: Sep 19, 2025

JSON object

Loading...
8.5
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security-advisories@github.com (Secondary)

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Starting in version 4.0.0-beta.18 and prior to 4.0.0-beta.253, a vulnerability in the execution of commands on remote servers allows an authenticated user to execute arbitrary code on the local Coolify container, gaining access to data and private keys or tokens of other users/teams. The ability to inject malicious commands into the Coolify container gives authenticated attackers the ability to fully retrieve and control the data and availability of the software. Centrally hosted Coolify instances (open registration and/or multiple teams with potentially untrustworthy users) are especially at risk, as sensitive data of all users and connected servers can be leaked by any user. Additionally, attackers are able to modify the running software, potentially deploying malicious images to remote nodes or generally changing its behavior. Version 4.0.0-beta.253 patches this issue.

Affected (234)

Products: Coollabs: Coolify
1 product
Coolify
Configuration A
234 vulnerable
Vulnerable SoftwareAffected Versions
Coollabs
Version 4.0.0 beta100
Version 4.0.0 beta101
Version 4.0.0 beta102
Version 4.0.0 beta103
Version 4.0.0 beta104
Version 4.0.0 beta105
Version 4.0.0 beta106
Version 4.0.0 beta107
Version 4.0.0 beta108
Version 4.0.0 beta109
Version 4.0.0 beta110
Version 4.0.0 beta111
Version 4.0.0 beta112
Version 4.0.0 beta113
Version 4.0.0 beta114
Version 4.0.0 beta115
Version 4.0.0 beta116
Version 4.0.0 beta117
Version 4.0.0 beta118
Version 4.0.0 beta119
Version 4.0.0 beta120
Version 4.0.0 beta121
Version 4.0.0 beta122
Version 4.0.0 beta123
Version 4.0.0 beta124
Version 4.0.0 beta125
Version 4.0.0 beta126
Version 4.0.0 beta127
Version 4.0.0 beta128
Version 4.0.0 beta129
Version 4.0.0 beta130
Version 4.0.0 beta131
Version 4.0.0 beta132
Version 4.0.0 beta133
Version 4.0.0 beta134
Version 4.0.0 beta135
Version 4.0.0 beta136
Version 4.0.0 beta137
Version 4.0.0 beta138
Version 4.0.0 beta139
Version 4.0.0 beta140
Version 4.0.0 beta141
Version 4.0.0 beta142
Version 4.0.0 beta143
Version 4.0.0 beta144
Version 4.0.0 beta145
Version 4.0.0 beta146
Version 4.0.0 beta147
Version 4.0.0 beta148
Version 4.0.0 beta149
Version 4.0.0 beta150
Version 4.0.0 beta151
Version 4.0.0 beta152
Version 4.0.0 beta153
Version 4.0.0 beta154
Version 4.0.0 beta155
Version 4.0.0 beta156
Version 4.0.0 beta157
Version 4.0.0 beta158
Version 4.0.0 beta159
Version 4.0.0 beta160
Version 4.0.0 beta161
Version 4.0.0 beta162
Version 4.0.0 beta163
Version 4.0.0 beta164
Version 4.0.0 beta165
Version 4.0.0 beta166
Version 4.0.0 beta167
Version 4.0.0 beta168
Version 4.0.0 beta169
Version 4.0.0 beta170
Version 4.0.0 beta171
Version 4.0.0 beta172
Version 4.0.0 beta173
Version 4.0.0 beta174
Version 4.0.0 beta175
Version 4.0.0 beta176
Version 4.0.0 beta177
Version 4.0.0 beta178
Version 4.0.0 beta179
Version 4.0.0 beta180
Version 4.0.0 beta181
Version 4.0.0 beta182
Version 4.0.0 beta183
Version 4.0.0 beta184
Version 4.0.0 beta185
Version 4.0.0 beta186
Version 4.0.0 beta187
Version 4.0.0 beta188
Version 4.0.0 beta189
Version 4.0.0 beta18
Version 4.0.0 beta190
Version 4.0.0 beta191
Version 4.0.0 beta192
Version 4.0.0 beta193
Version 4.0.0 beta194
Version 4.0.0 beta195
Version 4.0.0 beta196
Version 4.0.0 beta197
Version 4.0.0 beta198
Version 4.0.0 beta199
Version 4.0.0 beta19
Version 4.0.0 beta200
Version 4.0.0 beta201
Version 4.0.0 beta202
Version 4.0.0 beta203
Version 4.0.0 beta204
Version 4.0.0 beta205
Version 4.0.0 beta206
Version 4.0.0 beta207
Version 4.0.0 beta208
Version 4.0.0 beta209
Version 4.0.0 beta20
Version 4.0.0 beta211
Version 4.0.0 beta212
Version 4.0.0 beta213
Version 4.0.0 beta214
Version 4.0.0 beta215
Version 4.0.0 beta216
Version 4.0.0 beta217
Version 4.0.0 beta218
Version 4.0.0 beta219
Version 4.0.0 beta21
Version 4.0.0 beta220
Version 4.0.0 beta221
Version 4.0.0 beta222
Version 4.0.0 beta223
Version 4.0.0 beta224
Version 4.0.0 beta225
Version 4.0.0 beta226
Version 4.0.0 beta227
Version 4.0.0 beta228
Version 4.0.0 beta229
Version 4.0.0 beta22
Version 4.0.0 beta230
Version 4.0.0 beta231
Version 4.0.0 beta232
Version 4.0.0 beta233
Version 4.0.0 beta234
Version 4.0.0 beta235
Version 4.0.0 beta236
Version 4.0.0 beta237
Version 4.0.0 beta238
Version 4.0.0 beta239
Version 4.0.0 beta23
Version 4.0.0 beta240
Version 4.0.0 beta241
Version 4.0.0 beta242
Version 4.0.0 beta243
Version 4.0.0 beta244
Version 4.0.0 beta245
Version 4.0.0 beta246
Version 4.0.0 beta247
Version 4.0.0 beta248
Version 4.0.0 beta249
Version 4.0.0 beta24
Version 4.0.0 beta250
Version 4.0.0 beta251
Version 4.0.0 beta252
Version 4.0.0 beta25
Version 4.0.0 beta26
Version 4.0.0 beta27
Version 4.0.0 beta28
Version 4.0.0 beta29
Version 4.0.0 beta30
Version 4.0.0 beta31
Version 4.0.0 beta32
Version 4.0.0 beta33
Version 4.0.0 beta34
Version 4.0.0 beta35
Version 4.0.0 beta36
Version 4.0.0 beta37
Version 4.0.0 beta38
Version 4.0.0 beta39
Version 4.0.0 beta40
Version 4.0.0 beta41
Version 4.0.0 beta42
Version 4.0.0 beta43
Version 4.0.0 beta44
Version 4.0.0 beta45
Version 4.0.0 beta46
Version 4.0.0 beta47
Version 4.0.0 beta48
Version 4.0.0 beta49
Version 4.0.0 beta50
Version 4.0.0 beta51
Version 4.0.0 beta52
Version 4.0.0 beta53
Version 4.0.0 beta54
Version 4.0.0 beta55
Version 4.0.0 beta56
Version 4.0.0 beta57
Version 4.0.0 beta58
Version 4.0.0 beta59
Version 4.0.0 beta60
Version 4.0.0 beta61
Version 4.0.0 beta62
Version 4.0.0 beta63
Version 4.0.0 beta64
Version 4.0.0 beta65
Version 4.0.0 beta66
Version 4.0.0 beta67
Version 4.0.0 beta68
Version 4.0.0 beta69
Version 4.0.0 beta70
Version 4.0.0 beta71
Version 4.0.0 beta72
Version 4.0.0 beta73
Version 4.0.0 beta74
Version 4.0.0 beta75
Version 4.0.0 beta76
Version 4.0.0 beta77
Version 4.0.0 beta78
Version 4.0.0 beta79
Version 4.0.0 beta80
Version 4.0.0 beta81
Version 4.0.0 beta82
Version 4.0.0 beta83
Version 4.0.0 beta84
Version 4.0.0 beta85
Version 4.0.0 beta86
Version 4.0.0 beta87
Version 4.0.0 beta88
Version 4.0.0 beta89
Version 4.0.0 beta90
Version 4.0.0 beta91
Version 4.0.0 beta92
Version 4.0.0 beta93
Version 4.0.0 beta94
Version 4.0.0 beta95
Version 4.0.0 beta96
Version 4.0.0 beta97
Version 4.0.0 beta98
Version 4.0.0 beta99

References (5)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
ExploitVendor Advisory

Timeline

No history available yet.