Vulnerabilidades en coollabsio

73 resultados
Análisis Vexday

A Coollabs acumula 71 vulnerabilidades no histórico, com 46 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas. Embora nenhuma esteja sob exploração ativa no momento, 19 são classificadas como críticas, predominantemente relacionadas a injeção de comandos (CWE-78), o que representa risco significativo se explorado. A concentração recente de divulgações requer monitoramento atento e priorização de patches críticos.

CVE-2026-34153HIGHCoolify LocalFileVolume fs_path command injection enables RCEEPSS 0.8%CVE-2025-22609CRITICALCoolify Vulnerable to Private Key Hijacking / Remote Command Execution (RCE)EPSS 0.8%CVE-2026-34047CRITICALCoolify: WebSocket Endpoint Access Control Flaw Leading to Remote Code ExecutionEPSS 0.7%CVE-2026-34158HIGHCoolify: Command injection via single-quote breakout in Docker Compose custom commandsEPSS 0.7%CVE-2026-34058HIGHCoolify: OS Command Injection via Unmanaged Container Operations - Remote Code ExecutionEPSS 0.7%CVE-2026-34152HIGHCoolify: Command Injection via Newline in Pre/Post Deployment Commands (Heredoc Transport)EPSS 0.7%CVE-2026-42153HIGHCoolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in ContainerEPSS 0.7%CVE-2026-42204HIGHCoolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host rootEPSS 0.7%CVE-2025-64419CRITICALCoolify vulnerable to command injection via docker-compose.yaml parametersEPSS 0.6%CVE-2026-34035HIGHCoolify: Host RCE via Log Drain secret/env command injectionEPSS 0.6%CVE-2026-34057HIGHCoolify: Authenticated Remote Code Execution via Command Injection in Database Import Container NameEPSS 0.6%CVE-2025-22612CRITICALCoolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE)EPSS 0.6%CVE-2026-41899MEDIUMCoolify unauthenticated feedback endpoint allows Discord webhook abuseEPSS 0.5%CVE-2025-22605HIGHCoolify OS Command Injection Vulnerability in SSH Command GenerationEPSS 0.5%CVE-2025-64420CRITICALCoolify members can see private key of root userEPSS 0.5%CVE-2025-22611CRITICALCoolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE)EPSS 0.5%CVE-2025-59158CRITICALCoolify has Stored XSS in Project NameEPSS 0.5%CVE-2026-84694HIGHCoolify before 4.2.0 Remote Code Execution via Environment Variable KeyEPSS 0.5%CVE-2026-42147MEDIUMCoolify: SSRF via S3 Storage Endpoint in testConnection()EPSS 0.4%CVE-2026-34037CRITICALCross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()EPSS 0.4%