Vulnerability Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping or validation, allowing an authenticated member to inject shell metacharacters and execute commands as root when volume operations are triggered. This issue appears to be fixed in version 4.0.0-beta.471.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/coollabsio/coolify/commit/d2064dd4998694cda2eabd00149f7c4d1e9
- https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471
- https://github.com/coollabsio/coolify/security/advisories/GHSA-6pmw-6m96-4v4m
- https://github.com/coollabsio/coolify/security/advisories/GHSA-6pmw-6m96-4v4m
FAQ
What is CVE-2026-42143?
CVE-2026-42143 is a vulnerability with a CVSS score of 8.8 (HIGH). Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell command...
How severe is CVE-2026-42143?
CVE-2026-42143 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42143?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.