CVE-2026-42204: Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELLSAFECOMMANDPATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an authenticated team member to inject shell commands that execute on the host. This issue is fixed in version 4.0.0-beta.474.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolifyto a version that resolves this vulnerability.Fixed in 4.0.0-beta.474
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42204?
CVE-2026-42204 has a high severity score of 8.8.
What does CVE-2026-42204 affect?
CVE-2026-42204 affects Coolify versions from 4.0.0-beta.471 to 4.0.0-beta.473.
How do I fix CVE-2026-42204?
To fix CVE-2026-42204, upgrade to a patched version of Coolify that addresses the SHELL_SAFE_COMMAND_PATTERN regression.
What type of vulnerability is CVE-2026-42204?
CVE-2026-42204 is categorized as an OS Command Injection vulnerability.
What is the main risk of CVE-2026-42204?
The main risk of CVE-2026-42204 is authenticated remote code execution via manipulated Docker Compose commands.