Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root on the Coolify instance. As of time of publication, it is unclear if a patch is available.
The CWE-77 (command injection) vulnerability consists of insufficient validation and sanitization of user-supplied data in configuration fields of the git source assigned to a resource. A user with the 'member' role (low privileges) can craft malicious input containing additional system commands. This data is then passed to system calls without proper escaping, resulting in execution with root privileges on the Coolify host.
An attacker with the 'member' role can execute arbitrary system commands with root privileges, leading to complete takeover of the Coolify instance, managed servers, applications, and databases.
At the time of vulnerability publication, there was no certainty regarding patch availability. Track the official vendor repository and security advisory GHSA-qx24-jhwj-8w6x and apply patches according to vendor references immediately after release. Until updates are applied, it is recommended to restrict access to the Coolify instance only to trusted users and minimize the number of accounts with the 'member' role.
Coolify (Coollabs) in all versions up to v4.0.0-beta.434 inclusive
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCoollabs Coolify
APPCoollabs4.0.0< 4.0.0
Related vulnerabilities
Stored XSS w Coolify — atak przez złośliwą nazwę projektu
Command injection w Coolify via docker-compose.yaml — RCE jako root
RCE w Coolify — command injection w konfiguracji Docker Compose
Command injection w polu Git Repository w Coolify
Coolify: nieuprawniony dostęp do prywatnego klucza SSH użytkownika root