Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to inject arbitrary Docker Compose directives during project creation or updates. By defining a malicious service that mounts the host filesystem, an attacker can achieve root-level command execution on the host OS, completely bypassing container isolation. Version 4.0.0-beta.420.7 contains a patch for the issue.
An attacker with the role of a regular project member can define a malicious service in the Docker Compose configuration, mounting the host file system inside the container. This allows them to gain access to host resources outside the container environment. This results in privilege escalation to root level on the host operating system and complete takeover of the machine.
An attacker can obtain execution of arbitrary code with root privileges on the host (RCE), leading to complete server takeover, loss of data confidentiality, and violation of integrity and availability of all systems running on that host.
Coolify should be updated to version 4.0.0-beta.420.7 or newer, which contains a patch resolving the issue. According to the vendor's references, an advisory is available at https://github.com/coollabsio/coolify/security/advisories/GHSA-h5xw-7xvp-xrxr
Coolify (Coollabs) in versions earlier than 4.0.0-beta.420.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCoollabs Coolify
APPCoollabs4.0.0< 4.0.0
Related vulnerabilities
Command injection w Coolify via docker-compose.yaml — RCE jako root
Coolify: nieuprawniony dostęp do prywatnego klucza SSH użytkownika root
Command injection w polu Git Repository w Coolify
Stored XSS w Coolify — atak przez złośliwą nazwę projektu
Command injection w Coolify — wykonanie poleceń jako root przez użytkownika