GPU VulnDB

Database/Container, Kubernetes & orchestration

Coolify: low-privileged member injects Docker Compose directives and gets root on the host

CVSS 9.4CVE-2025-59156Container, Kubernetes & orchestrationcurated

Impact

Any member with permission to create or update a project can inject arbitrary Docker Compose directives - for example a service that bind-mounts the host filesystem - and execute commands as root on the host OS, bypassing container isolation entirely. On a machine that also runs workloads, that means the lowest deployment role on the Coolify instance becomes root over everything scheduled on that host, including other tenants' containers and any credentials or model artifacts mounted into them. The deployment control plane itself is the escalation path, so restricting container capabilities downstream does not help.

Who can reach it

A remote, authenticated user holding only low-privileged member rights on the Coolify instance. No host access and no admin role needed.

What to do

Upgrade Coolify to 4.0.0-beta.420.7 or later and restart the Coolify services; the fix is in that release per the GitHub advisory. Until the upgrade, treat every member who can edit a project as equivalent to host root and cut the member list down accordingly. Rollout is a control-plane restart, not a node reboot, but any host already managed by a vulnerable instance with untrusted members should be considered compromised and rebuilt.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.