CVE-2026-42153
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL heal
CVSS
8.8
High
EPSS
0.4%
p28
KEV
—
Exploit Today
8
0-100
Published: Jul 6, 2026 · Last modified: Jul 7, 2026 · CWE-78
0.4%EPSS · 30 days0.4%
2026-07-072026-07-21
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an authenticated user to inject commands executed in the database container. This issue is fixed in version 4.0.0-beta.474.
- github.comhttps://github.com/coollabsio/coolify/commit/b74f54302b1a857c22c55fe1210d700859b0b3df
- github.comhttps://github.com/coollabsio/coolify/pull/9674
- github.comhttps://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474
- github.comhttps://github.com/coollabsio/coolify/security/advisories/GHSA-gvc4-f276-r88p
- github.comhttps://github.com/coollabsio/coolify/security/advisories/GHSA-gvc4-f276-r88p
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-164895.3 MED—
——0A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.5hCVE-2026-164885.0 MED—
——0A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.1.0-rc1 is able to resolve this issue. This patch is called 9d868dc2550f426c6ddf8ee98f30ffe450ca5e32. It is suggested to upgrade the affected component.5hCVE-2026-8986——
——0Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.7hCVE-2026-8985——
——0Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.7hCVE-2026-648818.8 HIG—
——0The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.8hCVE-2026-648799.9 CRI—
——0A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.9h