CVE-2025-64419 | coollabsio coolify prior 4.0.0-beta.445 docker-compose.yaml command injection (GHSA-234r-xrrg-m8f3 / WID-SEC-2026-0031)
A vulnerability labeled as critical has been found in coollabsio coolify 4.0.0-beta.253/4.0.0-beta.359/4.0.0-beta.361/4.0.0-beta.374/4.0.0-beta.420.7. Impacted is an unknown function of the file docker-compose.yaml. Such manipulation leads to command injection.
This vulnerability is listed as CVE-2025-64419. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.