CVE-2025-64420: fallo crítico en coollabsio coolify
Coolify members can see private key of root user
Publicada el
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 10epss 0.5%
probabilidad de explotación
0.5%top 57% de las CVE
explotación observada
noninguna fuente lo reporta
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and authenticate as root user, using the private key. As of time of publication, it is unclear if a patch is available.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Productos afectados
coollabsio · coolifyCVEs relacionadas — coollabsio coolify
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-66209CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database BackupEPSS 3.9%CVE-2025-66213CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Directory Mount PathEPSS 3.1%CVE-2025-66212CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Configuration FilenameEPSS 3.1%CVE-2026-34599HIGHCoolify: Authenticated Remote Code Execution in GetLogs Livewire ComponentEPSS 2.8%CVE-2025-66211CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script FilenameEPSS 2.7%CVE-2025-66210CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database ImportEPSS 2.7%