CVE-2026-34152: Coolify: Command Injection via Newline in Pre/Post Deployment Commands (Heredoc Transport)
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH heredoc transport that preserves newlines, allowing an authenticated user to inject additional shell statements that execute on the remote server during deployment. This issue is fixed in version 4.0.0-beta.471.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolifyto a version that resolves this vulnerability.Fixed in 4.0.0-beta.471
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34152?
CVE-2026-34152 has a severity rating of high, with a score of 8.8.
What type of vulnerability is CVE-2026-34152?
CVE-2026-34152 is categorized as an OS Command Injection vulnerability.
How do I fix CVE-2026-34152?
To fix CVE-2026-34152, upgrade Coolify to version 4.0.0-beta.471 or later.
What is the impact of CVE-2026-34152?
CVE-2026-34152 allows an authenticated user to execute arbitrary commands on the server due to command injection.
Who is affected by CVE-2026-34152?
CVE-2026-34152 affects users of Coolify versions prior to 4.0.0-beta.471.