CVE-2025-22605

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-22605
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22605.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-22605
Aliases
  • GHSA-9wqm-fg79-4748
Published
2025-01-24T14:54:18Z
Modified
2025-11-04T20:30:22.209125Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P CVSS Calculator
Summary
Coolify OS Command Injection Vulnerability in SSH Command Generation
Details

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Starting in version 4.0.0-beta.18 and prior to 4.0.0-beta.253, a vulnerability in the execution of commands on remote servers allows an authenticated user to execute arbitrary code on the local Coolify container, gaining access to data and private keys or tokens of other users/teams. The ability to inject malicious commands into the Coolify container gives authenticated attackers the ability to fully retrieve and control the data and availability of the software. Centrally hosted Coolify instances (open registration and/or multiple teams with potentially untrustworthy users) are especially at risk, as sensitive data of all users and connected servers can be leaked by any user. Additionally, attackers are able to modify the running software, potentially deploying malicious images to remote nodes or generally changing its behavior. Version 4.0.0-beta.253 patches this issue.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ]
}
References

Affected packages

Git / github.com/coollabsio/coolify

Affected ranges

Type
GIT
Repo
https://github.com/coollabsio/coolify
Events

Affected versions

4.*

4.0.0-beta.39
4.0.0-beta.40

v4.*

v4.0.0-beta.100
v4.0.0-beta.101
v4.0.0-beta.102
v4.0.0-beta.103
v4.0.0-beta.104
v4.0.0-beta.105
v4.0.0-beta.106
v4.0.0-beta.107
v4.0.0-beta.108
v4.0.0-beta.109
v4.0.0-beta.110
v4.0.0-beta.111
v4.0.0-beta.112
v4.0.0-beta.113
v4.0.0-beta.114
v4.0.0-beta.115
v4.0.0-beta.116
v4.0.0-beta.117
v4.0.0-beta.118
v4.0.0-beta.119
v4.0.0-beta.120
v4.0.0-beta.121
v4.0.0-beta.122
v4.0.0-beta.123
v4.0.0-beta.124
v4.0.0-beta.125
v4.0.0-beta.126
v4.0.0-beta.127
v4.0.0-beta.128
v4.0.0-beta.129
v4.0.0-beta.130
v4.0.0-beta.131
v4.0.0-beta.132
v4.0.0-beta.133
v4.0.0-beta.134
v4.0.0-beta.135
v4.0.0-beta.136
v4.0.0-beta.137
v4.0.0-beta.138
v4.0.0-beta.139
v4.0.0-beta.140
v4.0.0-beta.141
v4.0.0-beta.142
v4.0.0-beta.143
v4.0.0-beta.144
v4.0.0-beta.145
v4.0.0-beta.146
v4.0.0-beta.147
v4.0.0-beta.148
v4.0.0-beta.149
v4.0.0-beta.150
v4.0.0-beta.151
v4.0.0-beta.152
v4.0.0-beta.153
v4.0.0-beta.154
v4.0.0-beta.155
v4.0.0-beta.156
v4.0.0-beta.157
v4.0.0-beta.158
v4.0.0-beta.159
v4.0.0-beta.160
v4.0.0-beta.161
v4.0.0-beta.162
v4.0.0-beta.163
v4.0.0-beta.164
v4.0.0-beta.165
v4.0.0-beta.166
v4.0.0-beta.167
v4.0.0-beta.168
v4.0.0-beta.169
v4.0.0-beta.170
v4.0.0-beta.171
v4.0.0-beta.172
v4.0.0-beta.173
v4.0.0-beta.174
v4.0.0-beta.175
v4.0.0-beta.176
v4.0.0-beta.177
v4.0.0-beta.178
v4.0.0-beta.179
v4.0.0-beta.18
v4.0.0-beta.180
v4.0.0-beta.181
v4.0.0-beta.182
v4.0.0-beta.183
v4.0.0-beta.184
v4.0.0-beta.185
v4.0.0-beta.186
v4.0.0-beta.187
v4.0.0-beta.188
v4.0.0-beta.189
v4.0.0-beta.19
v4.0.0-beta.190
v4.0.0-beta.191
v4.0.0-beta.192
v4.0.0-beta.193
v4.0.0-beta.194
v4.0.0-beta.195
v4.0.0-beta.196
v4.0.0-beta.197
v4.0.0-beta.198
v4.0.0-beta.199
v4.0.0-beta.20
v4.0.0-beta.200
v4.0.0-beta.201
v4.0.0-beta.202
v4.0.0-beta.203
v4.0.0-beta.204
v4.0.0-beta.205
v4.0.0-beta.206
v4.0.0-beta.207
v4.0.0-beta.208
v4.0.0-beta.209
v4.0.0-beta.21
v4.0.0-beta.211
v4.0.0-beta.212
v4.0.0-beta.213
v4.0.0-beta.214
v4.0.0-beta.215
v4.0.0-beta.216
v4.0.0-beta.217
v4.0.0-beta.218
v4.0.0-beta.219
v4.0.0-beta.22
v4.0.0-beta.220
v4.0.0-beta.221
v4.0.0-beta.222
v4.0.0-beta.223
v4.0.0-beta.224
v4.0.0-beta.225
v4.0.0-beta.226
v4.0.0-beta.227
v4.0.0-beta.228
v4.0.0-beta.229
v4.0.0-beta.23
v4.0.0-beta.230
v4.0.0-beta.231
v4.0.0-beta.232
v4.0.0-beta.233
v4.0.0-beta.234
v4.0.0-beta.235
v4.0.0-beta.236
v4.0.0-beta.237
v4.0.0-beta.238
v4.0.0-beta.239
v4.0.0-beta.24
v4.0.0-beta.240
v4.0.0-beta.241
v4.0.0-beta.242
v4.0.0-beta.243
v4.0.0-beta.244
v4.0.0-beta.245
v4.0.0-beta.246
v4.0.0-beta.247
v4.0.0-beta.248
v4.0.0-beta.249
v4.0.0-beta.25
v4.0.0-beta.250
v4.0.0-beta.251
v4.0.0-beta.252
v4.0.0-beta.26
v4.0.0-beta.27
v4.0.0-beta.28
v4.0.0-beta.29
v4.0.0-beta.30
v4.0.0-beta.31
v4.0.0-beta.32
v4.0.0-beta.33
v4.0.0-beta.34
v4.0.0-beta.35
v4.0.0-beta.36
v4.0.0-beta.37
v4.0.0-beta.38
v4.0.0-beta.41
v4.0.0-beta.42
v4.0.0-beta.43
v4.0.0-beta.44
v4.0.0-beta.45
v4.0.0-beta.46
v4.0.0-beta.47
v4.0.0-beta.48
v4.0.0-beta.49
v4.0.0-beta.50
v4.0.0-beta.51
v4.0.0-beta.52
v4.0.0-beta.53
v4.0.0-beta.54
v4.0.0-beta.55
v4.0.0-beta.56
v4.0.0-beta.57
v4.0.0-beta.58
v4.0.0-beta.59
v4.0.0-beta.60
v4.0.0-beta.61
v4.0.0-beta.62
v4.0.0-beta.63
v4.0.0-beta.64
v4.0.0-beta.65
v4.0.0-beta.66
v4.0.0-beta.67
v4.0.0-beta.68
v4.0.0-beta.69
v4.0.0-beta.70
v4.0.0-beta.71
v4.0.0-beta.72
v4.0.0-beta.73
v4.0.0-beta.74
v4.0.0-beta.75
v4.0.0-beta.76
v4.0.0-beta.77
v4.0.0-beta.78
v4.0.0-beta.79
v4.0.0-beta.80
v4.0.0-beta.81
v4.0.0-beta.82
v4.0.0-beta.83
v4.0.0-beta.84
v4.0.0-beta.85
v4.0.0-beta.86
v4.0.0-beta.87
v4.0.0-beta.88
v4.0.0-beta.89
v4.0.0-beta.90
v4.0.0-beta.91
v4.0.0-beta.92
v4.0.0-beta.93
v4.0.0-beta.94
v4.0.0-beta.95
v4.0.0-beta.96
v4.0.0-beta.97
v4.0.0-beta.98
v4.0.0-beta.99