CyberRota Analysis
AI-GeneratedCoolify versions prior to 4.0.0-beta.471 are vulnerable due to insufficient authorization checks on terminal websocket bootstrap routes, allowing low-privileged users to execute commands on team servers. This critical vulnerability poses a significant risk of unauthorized access and potential system compromise. Organizations using affected versions should prioritize upgrading to the fixed version to mitigate this security threat.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.