CVE-2026-42204
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.4
CVSS
8.8
High
EPSS
0.4%
p28
KEV
—
Exploit Today
8
0-100
Published: Jul 6, 2026 · Last modified: Jul 7, 2026 · CWE-78
0.4%EPSS · 30 days0.4%
2026-07-072026-07-21
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an authenticated team member to inject shell commands that execute on the host. This issue is fixed in version 4.0.0-beta.474.
- github.comhttps://github.com/coollabsio/coolify/commit/e1aac50b745cf499e710b7e35cd2a9d6a1538dd9
- github.comhttps://github.com/coollabsio/coolify/pull/9684
- github.comhttps://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474
- github.comhttps://github.com/coollabsio/coolify/security/advisories/GHSA-chg4-63hm-xv9x
- github.comhttps://github.com/coollabsio/coolify/security/advisories/GHSA-chg4-63hm-xv9x
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-164895.3 MED—
——0A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.5hCVE-2026-164885.0 MED—
——0A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.1.0-rc1 is able to resolve this issue. This patch is called 9d868dc2550f426c6ddf8ee98f30ffe450ca5e32. It is suggested to upgrade the affected component.5hCVE-2026-8986——
——0Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.7hCVE-2026-8985——
——0Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.7hCVE-2026-648818.8 HIG—
——0The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.8hCVE-2026-648799.9 CRI—
——0A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.9h