Coollabs maintains a focused containerization and application-deployment platform, Coolify, that simplifies infrastructure management for developers and small to medium-sized deployments. Despite a narrow product portfolio, the platform has gained prominence in the landscape, and its vulnerabilities skew toward serious outcomes with a meaningful share reaching critical severity. The recurring weakness classes—OS command injection, missing authorization, input validation flaws, sensitive information exposure, and output encoding failures—reflect the risks inherent in a system that bridges user-facing interfaces with underlying infrastructure automation and container orchestration. Defenders should prioritize patches for this vendor given the elevation in severity, as flaws at the infrastructure-orchestration layer can afford attackers broad lateral movement and system compromise. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coollabs over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-34157CRITICAL Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges | Aug 27, 2025 | 9.0 | 34 | NO | NO |
CVE-2025-64419HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are | Jan 5, 2026 | 8.8 | 33 | NO | NO |
CVE-2025-66209HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit | Dec 23, 2025 | 8.8 | 33 | NO | NO |
CVE-2025-34161HIGH Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, wit | Aug 27, 2025 | 8.8 | 33 | NO | NO |
CVE-2025-64424HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vul | Jan 5, 2026 | 8.8 | 32 | NO | NO |
CVE-2025-64420HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users | Jan 5, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-34159HIGH Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, | Aug 27, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-22609CRITICAL Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authentica | Jan 24, 2025 | 10.0 | 31 | NO | NO |
CVE-2025-66213HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit | Dec 23, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-66212HIGH Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerabilit | Dec 23, 2025 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coollabs.
Media articles that mention a CVE ID that affects a product developed by Coollabs — matched by CVE ID, not by vendor name.