Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2025-66209
CriticalVulnerability Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in backup operations are passed directly to shell commands without sanitization, enabling full remote code execution. Version 4.0.0-beta.451 fixes the issue.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Known Affected Software
210 configuration(s) from 1 vendor(s)
cpe:2.3:a:coollabs:coolify:2.4.8:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.24:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.24:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.8:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.23:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.11:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.9:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.26:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.12:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.20:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.11:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.11:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.28:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.20:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.12:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta47:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.13:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.25:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.19:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.3.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.9.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.19:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.9:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.25:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.9:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.16:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.16:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.10:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.35:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.2.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.13:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.13:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.23:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.9.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.27:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.22:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.8:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.9:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.18:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.13:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.10:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.13:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.24:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.17:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.2.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.9.0:-:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.10:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.15:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.9:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.31:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.9:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.14:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.18:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.15:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.14:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.10:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.8:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.16:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.21:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.36:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.22:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.11:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.21:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.26:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.16:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.17:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.12:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.8.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.15:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.21:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.15:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.12:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.29:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.27:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.6:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.30:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.23:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.32:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.30:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.14:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.18:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.10:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.22:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.14:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.31:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.3.4:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.29:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.20:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.11.11:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.2.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.37:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.4.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.10.12:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.8:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.7:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.0.32:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.33:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.17:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.28:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:1.0.10:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:2.9.8:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.9.3:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.12.19:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:3.9.1:-:*:*:*:*:*:*
References & Resources
-
https://github.com/0xrakan/coolify-cve-2025-66209-66213security-advisories@github.com Exploit Third Party Advisory
-
https://github.com/coollabsio/coolify/pull/7375security-advisories@github.com Issue Tracking Patch
-
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.451security-advisories@github.com Release Notes
-
https://github.com/coollabsio/coolify/security/advisories/GHSA-vm5p-43qh-7pmqsecurity-advisories@github.com Exploit Vendor Advisory
Severity Details
Key Information
- Published Date
- December 23, 2025
