CyberRota Analysis
AI-GeneratedCoolify versions prior to 4.0.0-beta.466 are vulnerable due to inadequate protection on mutating API validation endpoints, allowing read-scoped API tokens to execute state-changing operations like validating cloud tokens and servers. This could lead to unauthorized modifications and potential compromise of server management. Organizations using affected versions should prioritize upgrading to the fixed version to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating cloud tokens and servers. This issue is fixed in version 4.0.0-beta.466.