CVE-2026-84694
Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.
Zwakheid
Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.
Bronnen
- https://github.com/coollabsio/coolify
- https://github.com/coollabsio/coolify/blob/v4.1.2/app/Policies/ApplicationPolicy.php
- https://github.com/coollabsio/coolify/blob/v4.1.2/app/Support/ValidationPatterns.php
- https://github.com/coollabsio/coolify/commit/b50839d4515b115b7ded5db609471440249995da
- https://github.com/coollabsio/coolify/releases/tag/v4.2.0
- https://www.vulncheck.com/advisories/coolify-before-4.2.0-remote-code-execution-via-environment-variable-key
Vind de bug voordat een aanvaller dat doet.
Log in met GitHub en start je eerste audit binnen een minuut. Voor het gratis abonnement is geen creditcard nodig.