Cyber Resilience

CVE-2025-66212

CriticalPublic PoCRCE

Published: 23 December 2025

Published
23 December 2025
Modified
17 March 2026
KEV Added
Patch
CVSS Score v4 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0318 86.4th percentile
Risk Priority 21 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-66212 is a critical-severity OS Command Injection (CWE-78) vulnerability in Coollabs Coolify. Its CVSS base score is 9.4 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Unix Shell (T1059.004); ranked in the top 13.6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).

Deeper analysis

Coolify, an open-source and self-hostable tool for managing servers, applications, and databases, is affected by CVE-2025-66212, an authenticated command injection vulnerability (CWE-78) in the Dynamic Proxy Configuration Filename handling prior to version 4.0.0-beta.451. The flaw occurs because proxy configuration filenames are passed directly to shell commands without proper escaping, allowing injection of malicious payloads.

Attackers with application or service management permissions can exploit this vulnerability remotely over the network (AV:N) with low attack complexity (AC:L), low privileges required (PR:L), and no user interaction (UI:N), resulting in high impacts to confidentiality, integrity, and availability (CVSS 8.8; CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Exploitation enables execution of arbitrary commands as root on managed servers, leading to full remote code execution.

Version 4.0.0-beta.451 addresses the vulnerability by fixing the command injection issue. Official mitigation guidance is provided in the Coolify security advisory (GHSA-q7rg-2j7p-83gp), the associated pull request (#7375), and the release notes for v4.0.0-beta.451. Security practitioners should upgrade affected instances immediately.

EU & UK References

Vulnerability details

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Dynamic Proxy Configuration Filename handling allows users with application/service management permissions to execute arbitrary commands as…

more

root on managed servers. Proxy configuration filenames are passed to shell commands without proper escaping, enabling full remote code execution. Version 4.0.0-beta.451 fixes the issue.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1059.004 Unix Shell Execution
Adversaries may abuse Unix shell commands and scripts for execution.
T1210 Exploitation of Remote Services Lateral Movement
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

Authenticated command injection (CWE-78) in proxy configuration directly enables Unix Shell execution (T1059.004), exploitation of remote service (T1210), and privilege escalation to root (T1068).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2025-66211Same product: Coollabs Coolify
CVE-2025-59156Same product: Coollabs Coolify
CVE-2025-66209Same product: Coollabs Coolify
CVE-2025-22605Same product: Coollabs Coolify
CVE-2025-66210Same product: Coollabs Coolify
CVE-2025-34161Same product: Coollabs Coolify
CVE-2025-22606Same product: Coollabs Coolify
CVE-2025-66213Same product: Coollabs Coolify
CVE-2025-59157Same product: Coollabs Coolify
CVE-2025-64424Same product: Coollabs Coolify

Affected Assets

coollabs
coolify
4.0.0 · ≤ 4.0.0

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Requires validation and sanitization of proxy configuration filenames before passing to shell commands, directly preventing command injection exploits.

prevent

Mandates identification, reporting, and timely correction of the command injection flaw through patching to version 4.0.0-beta.451.

prevent

Enforces least privilege on Coolify processes to restrict arbitrary command execution to non-root even if injection succeeds.

References