CyberRota Analysis
AI-GeneratedCoolify versions prior to 4.0.0-beta.466 are vulnerable due to improper validation of the sentinel_token setting, which allows authenticated users to inject shell commands that can be executed on the host during a Sentinel restart. This vulnerability poses a high risk as it can lead to unauthorized command execution, potentially compromising the server's integrity and security. Organizations using Coolify for server management should prioritize upgrading to the fixed version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing an authenticated user with access to server Sentinel settings to inject shell syntax and execute commands on the host when Sentinel is restarted. This issue is fixed in version 4.0.0-beta.466.