CyberRota Analysis
AI-GeneratedCoolify versions prior to 4.0.0-beta.466 are vulnerable to command injection due to insufficient encoding of log drain secrets and environment values within shell commands. This flaw allows authenticated users to execute arbitrary commands on the host, posing a significant security risk. Organizations using Coolify should prioritize upgrading to the fixed version to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands without sufficient encoding, allowing an authenticated user to inject commands executed on the host. This issue is fixed in version 4.0.0-beta.466.