Root command execution via unescaped volume source
Published Jan 5, 2026 · Updated Jan 5, 2026
Command injection in coolLabs Coolify before 4.0.0-beta.445 allows remote attackers to execute commands as root via a malicious repository. The executeInDocker helper embeds the Docker Compose volumes.source value in a docker exec bash -c command without escaping shell metacharacters. A Coolify user must create and deploy a Docker Compose application from the attacker-controlled repository, after which injected shell syntax runs on the host with root privileges.
Summary
What happened
Command injection in coolLabs Coolify before 4.0.0-beta.445 allows remote attackers to execute commands as root via a malicious repository. The executeInDocker helper embeds the Docker Compose volumes.source value in a docker exec bash -c command without escaping shell metacharacters. A Coolify user must create and deploy a Docker Compose application from the attacker-controlled repository, after which injected shell syntax runs on the host with root privileges.
The record
- CVE
- CVE-2025-64419
- Published
- Jan 5, 2026
- Updated
- Jan 5, 2026
- Vendor
- coolLabs
- Product
- Coolify
- Classifications
- CWE-77, T1204.002
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jan 5, 2026CVE publishedPublication date reported by the CVE source.
- Jan 5, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=< 4.0.0-beta.445
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Docker Compose volumes.source command-injection proof of conceptfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo