CyberRota Analysis
AI-GeneratedA vulnerability in Coolify versions 4.0.0-beta.471 to 4.0.0-beta.473 allows authenticated users to inject shell commands into custom Docker Compose commands, potentially executing arbitrary commands on the host system. This poses a significant risk to the integrity and security of the host environment, making it critical for organizations using affected versions to upgrade to 4.0.0-beta.474 immediately. Teams managing Docker environments should prioritize this update to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an authenticated team member to inject shell commands that execute on the host. This issue is fixed in version 4.0.0-beta.474.