CVE-2026-59734: Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generatehealthcheckcommands() function directly interpolated the healthcheckhost, healthcheckmethod, and healthcheckpath parameters into shell commands without proper sanitization, allowing authenticated users to execute arbitrary commands inside deployment containers. This issue is fixed in version 4.0.0-beta.469.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolifyto a version that resolves this vulnerability.Fixed in 4.0.0-beta.469
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59734?
CVE-2026-59734 has a severity rating of high at 8.8.
What type of vulnerability is CVE-2026-59734?
CVE-2026-59734 is classified as an OS command injection vulnerability.
How do I fix CVE-2026-59734?
To fix CVE-2026-59734, you should upgrade Coolify to version 4.0.0-beta.469 or later.
What impact does CVE-2026-59734 have on my system?
CVE-2026-59734 can allow remote code execution, posing a significant security risk.
Which versions of Coolify are affected by CVE-2026-59734?
CVE-2026-59734 affects all versions of Coolify prior to 4.0.0-beta.469.