CVE-2026-34152General

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH heredoc transport that preserves newlines, allowing an authenticated user to inject additional shell statements that execute on the remote server during deployment. This issue is fixed in version 4.0.0-beta.471.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-07); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-07-07: 2Mentions · 2026-07-08: 2Patch / Workaround · 2026-07-08: 2Technical Details · 2026-07-08: 207-0707-08
Signal classification2 categories
General
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-072
General2
2026-07-082
Patch2
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-34152 - OS Command #Injection in Coolify. Authenticated users can inject shell commands via pre/post-deployment scripts. #CVSS 8.8. Update to 4.0.0-beta.471 immediately. #CVEAlert #Coolify #infosec #devsecops #devops #developers #sysadmin https://www.valtersit.com/cve/CVE-2026-34152/

    Post summary

    The post highlights a known OS command injection flaw in Coolify with a CVSS of 8.8 and urges users to update to version 4.0.0-beta.471 to mitigate the risk.

    0000060
    974 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-34152 - OS Command Injection in #Coolify. Authenticated users can inject shell commands via pre/post-deployment #scripts. #CVSS 8.8. Update to 4.0.0-beta.471 immediately. #CVEAlert #DevOps #devsecops #developers #cybersecurity #infosec #redteam #blueteam https://www.valtersit.com/cve/CVE-2026-34152/

    Post summary

    CVE‑2026‑34152 is an OS command‑injection flaw in Coolify that scores 8.8 on the CVSS; the vendor recommends updating to version 4.0.0‑beta.471 to mitigate the issue.

    0000053
    974 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34152 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment comman… https://www.cve.org/CVERecord?id=CVE-2026-34152 ----- Traducción: CVE-2026-34152 Coo… http://infoflow.cloud`

    Post summary

    The content references CVE-2026-34152 for Coolify but offers no additional details on exploitation, patches, or technical specifics.

    0000033
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34152 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment comman… https://www.cve.org/CVERecord?id=CVE-2026-34152

    Post summary

    The snippet only references CVE-2026-34152 with a link and provides no further details on the vulnerability.

    00000679
    57.8K followersView on X

Explore more