CVE-2025-64420 CRITICAL

CVE-2025-64420: Coolify members can see private key of root user

Vendor Coollabsio
Product coolify
Weakness CWE-522 · Insufficiently protected credentials
Published January 5, 2026
Last update January 5, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and authenticate as root user, using the private key. As of time of publication, it is unclear if a patch is available.

Key dates

02Disclosure timeline

January 5, 2026 CVE published
January 5, 2026 Record updated