2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-42143 — Coolify: Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42143

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping or validation, allowing an authenticated member to inject shell metacharacters and execute commands as root when volume operations are triggered. This issue appears to be fixed in version 4.0.0-beta.471. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34171 — Coolify: Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34171

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password to a predictable value. This issue is fixed in version 4.0.0-beta.471. CVSSv3.1 8.0 (HIGH)

CWECWE 352VNDCoolifyTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34168 — Coolify: Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34168

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument escaping, allowing an authenticated user to set a storage name containing shell metacharacters and execute commands on managed servers when the resource is deleted. This issue is fixed in version 4.0.0-beta.471. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34152 — Coolify: Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34152

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH heredoc transport that preserves newlines, allowing an authenticated user to inject additional shell statements that execute on the remote server during deployment. This issue is fixed in version 4.0.0-beta.471. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34058 — Coolify: Prior to 4.0.0-beta.471, the Livewire component Server\Resources exposes public methods (startUnmanaged, stopUnmanaged, restartUnmanaged) that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34058

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Livewire component Server\Resources exposes public methods (startUnmanaged, stopUnmanaged, restartUnmanaged) that accept a container ID parameter directly from the browser without any sanitization or escaping. This parameter is interpolated directly into shell commands executed via SSH on managed servers, enabling any authenticated team member to ex CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34057 — Coolify: Prior to 4.0.0-beta.471, the database import Livewire component (app/Livewire/Project/Database/Import.php) allows client-controlled container and server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34057

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the database import Livewire component (app/Livewire/Project/Database/Import.php) allows client-controlled container and server properties to reach shell commands without locking or validation, allowing an authenticated user to inject commands through a database import container name. This issue is fixed in version 4.0.0-beta.471. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
CRIT

CVE-2026-34048 — Coolify: Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34048

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862CWECWE 285VNDCoolifyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-07
2026-07-07 04:17Z
CRIT

CVE-2026-34047 — Coolify: Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34047

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware, allowing an authenticated user to access terminal functionality for resources outside the authorized scope and potentially execute commands. This issue is fixed in version 4.0.0-beta.471. CVSSv3.1 9.9 (CRITICAL)

CWECWE 863VNDCoolifyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-07
2026-07-07 04:17Z
CRIT

CVE-2026-34037 — Coolify: Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34037

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups, allowing an authenticated user to clone resources into destinations owned by other teams and access cross-tenant resources. This issue is fixed in version 4.0.0-beta.464. CVSSv3.1 9.9 (CRITICAL)

CWECWE 639VNDCoolifyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34035 — Coolify: Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34035

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands without sufficient encoding, allowing an authenticated user to inject commands executed on the host. This issue is fixed in version 4.0.0-beta.466. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34034 — Coolify: Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34034

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing an authenticated user with access to server Sentinel settings to inject shell syntax and execute commands on the host when Sentinel is restarted. This issue is fixed in version 4.0.0-beta.466. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 00:00Z
MED

2607_agents_vs_telemetry

Sophos X-Ops·news.sophos.com

Sophos X-Ops analyzed behavioral telemetry from their CIXA endpoint detection engine showing how legitimate AI coding agents (Claude Code, Cursor, Codex, GStack) trigger security rules designed to catch adversary activity. The agents perform credential access via DPAPI decryption, browser automation, credential dumping, LOLBin-based downloads with fallback pivoting, and startup-folder persistence writes—activities indistinguishable from attacker tradecraft. The analysis demonstrates that existing behavioral protections are functioning correctly but highlights the detection-engineering challenge of tuning rules to accommodate benign agentic AI while maintaining security posture.

SRFOsTACTA0004TACTA0002TACTA0006TACTA0003OSWindowsVNDSophosTYPResearch
72
Edit Score
2026-07-06
2026-07-06 22:16Z
HIGH

CVE-2026-42204 — Coolify: From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42204

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an authenticated team member to inject shell commands that execute on the host. This issue is fixed in version 4.0.0-beta.474. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 22:16Z
HIGH

CVE-2026-42153 — Coolify: Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42153

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an authenticated user to inject commands executed in the database container. This issue is fixed in version 4.0.0-beta.474. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 22:16Z
HIGH

CVE-2026-34599 — Coolify: Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34599

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute arbitrary commands as root on managed servers. The $container Livewire public property is interpolated directly into shell commands (docker logs, docker service logs) without saniti CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 22:16Z
HIGH

CVE-2026-34153 — Coolify: Prior to 4.0.0-beta.471, LocalFileVolume::saveStorageOnServer builds shell commands using unescaped fs_path and parent_dir values before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34153

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, LocalFileVolume::saveStorageOnServer builds shell commands using unescaped fs_path and parent_dir values before validation, and submitFileStorage does not validate the user-controlled file-mount path before creating a volume, allowing an authenticated user who can add file storage to execute commands when the storage is saved. This issue is fixed in ver CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 21:16Z
HIGH

CVE-2026-59713 — Leantime: contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59713

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker. CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDLeantimeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 21:16Z
HIGH

CVE-2026-59712 — Users: Attackers can exploit this by calling users.getUser with arbitrary user IDs to enumerate all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59712

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens. Attackers can exploit this by calling users.getUser with arbitrary user IDs to enumerate all accounts and obtain credentials for offline password cracking, 2FA bypass, and session hijacking. CVSSv3.1 8.1 (HIGH)

CWECWE 639TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 21:16Z
HIGH

CVE-2026-57573 — Crawl4AI: Prior to 0.9.0, the Docker API server applied its SSRF destination check on the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57573

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validation, allowing a remote unauthenticated client to call POST /crawl/stream or POST /crawl with crawler_config.stream=true with a URL pointing at an internal, private, or link-local add CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDCrawl4aiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-06
2026-07-06 21:16Z
CRIT

CVE-2026-57572 — Crawl4AI: The Docker API is unauthenticated by default, so a single request yields arbitrary command

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57572

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user. The Docker API is unauthenticated by default, so a single request CVSSv3.1 10.0 (CRITICAL)

CWECWE 94CWECWE 88VNDCrawl4aiTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-06
2026-07-06 21:16Z
CRIT

CVE-2026-57571 — Crawl4AI: A filename containing an absolute path or traversal escaped the downloads directory, giving an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57571

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents; the HTTP crawler path uses the response Content-Disposition filename and the brow CVSSv3.1 9.6 (CRITICAL)

CWECWE 22CWECWE 59VNDCrawl4aiTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-06
2026-07-06 21:16Z
CRIT

CVE-2026-54763 — Traefik Traefik: Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54763

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches CVSSv3.1 10.0 (CRITICAL) · EPSS 19th percentile

CWECWE 345CWECWE 290CWECWE 178VNDTraefikTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-06
2026-07-06 21:16Z
CRIT

CVE-2026-34038 — Coolify: Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34038

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through deployment logs via fields such as dockerfile_location and deployment commands. This issue is fixed in version 4.0.0-beta.469. CVSSv3.1 9.9 (CRITICAL)

CWECWE 78VNDCoolifyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-06
2026-07-06 21:16Z
HIGH

CVE-2026-25268 — Memory: Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25268

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. CVSSv3.1 8.8 (HIGH)

CWECWE 121TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 21:16Z
HIGH

CVE-2026-14471 — Neutralization: Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14471

Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position. To remediate this issue, users should upgrade to version 1.0.13 or later. CVSSv3.1 8.1 (HIGH)

CWECWE 89TYPVulnerability
8.1
CVSS v3.1
91
Edit Score