CyberRota Analysis
AI-GeneratedCoolify versions prior to 4.0.0-beta.471 are vulnerable to command injection due to user-controlled persistent volume names being interpolated into shell commands without proper escaping or validation. This flaw allows authenticated users to execute arbitrary commands with root privileges on managed servers, posing a significant security risk. Organizations using affected versions should prioritize upgrading to the fixed version to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping or validation, allowing an authenticated member to inject shell metacharacters and execute commands as root when volume operations are triggered. This issue appears to be fixed in version 4.0.0-beta.471.