Coolify · Coolify · CVE-2026-34038
**Name of the Vulnerable Software and Affected Versions**
Coolify versions prior to 4.0.0-beta.469
**Description**
An authenticated remote command injection issue exists in the application deployment handling. Users with application write permissions can achieve remote code execution and exfiltrate sensitive environment variables through deployment logs by manipulating fields such as `dockerfile location` and deployment commands.
**Recommendations**
Update to version 4.0.0-beta.469.