CVE-2026-42143General

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping or validation, allowing an authenticated member to inject shell metacharacters and execute commands as root when volume operations are triggered. This issue appears to be fixed in version 4.0.0-beta.471.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-07); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-07: 2Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-0707-08
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-072
General2
2026-07-081
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-42143 (CVSS 8.8) Coolify command injection flaw allows authenticated users to execute commands as root via unvalidated volume names. Affects versions <4.0.0-beta.471. Patch immediately! #CVE #Vulnerability #PatchNow #CyberSecurity https://t.co/wyrT8r0qKS

    Post summary

    The tweet warns of a high‑severity command‑injection flaw (CVE‑2026‑42143) in Coolify, urges immediate patching, but gives no PoC, exploit code, or evidence of live attacks.

    0000053
    68 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-42143 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names a… https://www.cve.org/CVERecord?id=CVE-2026-42143 ----- Traducción: CVE-2026-42143 Coo… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑42143 and links to its CVE record but provides no additional technical, exploit, or remediation information.

    0000036
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42143 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names a… https://www.cve.org/CVERecord?id=CVE-2026-42143

    Post summary

    The text merely references CVE-2026-42143 with minimal context, lacking any proof of concept, exploit details, or patch information.

    00000639
    57.8K followersView on X

Explore more