Impact
Coolify versions prior to 4.2.0 do not properly escape environment variable key names in Docker commands executed over SSH on managed servers. This allows an authenticated attacker to inject shell metacharacters into the key names, causing those metacharacters to be interpreted by the host shell. The attacker can then run arbitrary commands on the server host, outside of any container boundaries, leading to full remote code execution on the host machine. The weakness is categorized as CWE‑78, reflecting an operating‑system command injection flaw.
Affected Systems
The affected vendor is CoollabsIO, product Coolify. All installations running any release before 4.2.0 that use Docker commands over SSH on managed servers are potentially exposed. Users should verify the installed version and determine whether they are operating with credentials that permit the creation or modification of Docker environment variable keys.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. With no EPSS score available and the issue not listed in the CISA KEV catalog, the likelihood of exploitation remains uncertain, but the impact is severe. An attacker only needs legitimate credentials to configure environment variables for Docker deployments, making the attack vector relatively low in terms of access requirements yet high in consequence. Until a patch is applied, systems should be treated as at risk of full host compromise.
OpenCVE Enrichment