CVE-2026-34153: Coolify LocalFileVolume fs_path command injection enables RCE
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, LocalFileVolume::saveStorageOnServer builds shell commands using unescaped fspath and parentdir values before validation, and submitFileStorage does not validate the user-controlled file-mount path before creating a volume, allowing an authenticated user who can add file storage to execute commands when the storage is saved. This issue is fixed in version 4.0.0-beta.471.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolify LocalFileVolumeto a version that resolves this vulnerability.Fixed in 4.0.0-beta.471
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34153?
The severity of CVE-2026-34153 is rated high with a CVSS score of 8.8.
What is CVE-2026-34153?
CVE-2026-34153 is a command injection vulnerability in Coolify that allows remote code execution using improperly handled inputs.
How do I fix CVE-2026-34153?
To fix CVE-2026-34153, upgrade to Coolify version 4.0.0-beta.471 or later, which addresses the input validation issue.
What could happen if CVE-2026-34153 is exploited?
If exploited, CVE-2026-34153 can lead to remote code execution on affected systems, potentially compromising sensitive data.
Which versions of Coolify are affected by CVE-2026-34153?
CVE-2026-34153 affects all versions of Coolify prior to 4.0.0-beta.471.