Vulnerability Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through deployment logs via fields such as dockerfile_location and deployment commands. This issue is fixed in version 4.0.0-beta.469.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/coollabsio/coolify/commit/23f9156c7306b221101f1ebbe4d3c6b5e25
- https://github.com/coollabsio/coolify/pull/9007
- https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.469
- https://github.com/coollabsio/coolify/security/advisories/GHSA-qqrq-r9h4-x6wp
- https://github.com/coollabsio/coolify/security/advisories/GHSA-qqrq-r9h4-x6wp
FAQ
What is CVE-2026-34038?
CVE-2026-34038 is a vulnerability with a CVSS score of 9.9 (CRITICAL). Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application depl...
How severe is CVE-2026-34038?
CVE-2026-34038 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-34038?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.