AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-42204

HIGH · CVSS 8.8 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

A vulnerability in Coolify versions 4.0.0-beta.471 to 4.0.0-beta.473 allows authenticated users to inject shell commands into custom Docker Compose commands, potentially executing arbitrary commands on the host system. This poses a significant risk to the integrity and security of the host environment, making it critical for organizations using affected versions to upgrade to 4.0.0-beta.474 immediately. Teams managing Docker environments should prioritize this update to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-42204
Severity
HIGH
CVSS
8.8
EPSS
0.36%
Docker

Original NVD Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an authenticated team member to inject shell commands that execute on the host. This issue is fixed in version 4.0.0-beta.474.