CVE-2026-59734
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/J
CVSS
8.8
High
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Jul 9, 2026 · Last modified: Jul 9, 2026 · CWE-78
0.4%EPSS · 30 days0.4%
2026-07-102026-07-19
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_method, and health_check_path parameters into shell commands without proper sanitization, allowing authenticated users to execute arbitrary commands inside deployment containers. This issue is fixed in version 4.0.0-beta.469.
- github.comhttps://github.com/coollabsio/coolify/commit/0ffcee7a4dcd24f92b5fab8c9c7be140b9532733
- github.comhttps://github.com/coollabsio/coolify/pull/9007
- github.comhttps://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.469
- github.comhttps://github.com/coollabsio/coolify/security/advisories/GHSA-4fhp-xqqp-w7vv
- github.comhttps://github.com/coollabsio/coolify/security/advisories/GHSA-4fhp-xqqp-w7vv
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-341978.8 HIG99.9%
KEV—80Apache ActiveMQ Improper Input Validation Vulnerability5dCVE-2024-121210.0 CRI99.9%
KEV—80Progress Kemp LoadMaster OS Command Injection Vulnerability7dCVE-2026-398089.8 CRI99.7%
KEV—80Fortinet FortiSandbox OS Command Injection Vulnerability3dCVE-2022-262589.8 CRI99.6%
KEV—80D-Link DIR-820L Remote Code Execution Vulnerability11dCVE-2026-422718.8 HIG99.6%
KEV—80BerriAI LiteLLM Command Injection Vulnerability5dCVE-2021-252988.8 HIG99.5%
KEV—80Nagios XI OS Command Injection11d