Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handling did not sufficiently restrict paths, allowing an authenticated user to write files outside the intended directory and achieve command execution through database initialization. This issue is fixed in version 4.0.0-beta.474.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-07 04:17
Updated : 2026-07-07 13:22
NVD link : CVE-2026-42200
Mitre link : CVE-2026-42200
CVE.ORG link : CVE-2026-42200
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
