{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/coolify/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:coolify:coolify:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-84694"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Coolify (\u003c 4.2.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","cloud"],"_cs_type":"advisory","_cs_vendors":["Coolify"],"content_html":"\u003cp\u003eCoolify versions prior to 4.2.0 contain a critical vulnerability identified as CVE-2026-84694. The flaw exists in how the application handles environment variable key names when constructing Docker commands for execution over SSH on managed host servers. Specifically, the application fails to properly sanitize or escape input, enabling an authenticated attacker to inject shell metacharacters into the environment variable key fields. When Coolify triggers a Docker command (such as 'docker run' or 'docker exec') using these unsanitized variables, the injected characters are interpreted by the host shell, resulting in arbitrary code execution outside the container context. This vulnerability poses a high risk to infrastructure security, as it allows escalation from the Coolify application interface to full host-level access on connected managed servers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to execute arbitrary commands on the host server where Coolify manages Docker containers. This effectively grants the attacker control over the host operating system, potentially leading to unauthorized data access, persistence, privilege escalation, and lateral movement within the infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of all Coolify instances to version 4.2.0 or later to remediate CVE-2026-84694. For infrastructure hardening, restrict the permissions of the SSH service account used by Coolify to communicate with managed hosts, applying the principle of least privilege to limit the scope of potential command injection impact.\u003c/p\u003e\n","date_modified":"2026-09-02T03:10:31Z","date_published":"2026-09-02T03:10:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-coolify-command-injection/","summary":"Coolify versions before 4.2.0 are vulnerable to command injection via environment variable keys, allowing authenticated attackers to execute arbitrary commands on the underlying host server.","title":"Command Injection Vulnerability in Coolify","url":"https://feed.craftedsignal.io/briefs/2026-09-coolify-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Coolify","version":"https://jsonfeed.org/version/1.1"}