Impact
The vulnerability originates from the manipulation of the state argument in the GitHub App Setup redirect handler within Coolify. By altering this parameter the application fails to enforce authentication, allowing an attacker to complete the OAuth flow without proper verification. This represents an authentication bypass that could enable unauthorized API access or privilege escalation within the application. The description confirms that the exploit can be executed remotely and the adversary has already published the technique.
Affected Systems
CoollabsIO’s Coolify product, versions up to 4.1.0, is affected. The problem is resolved in release 4.1.1, which incorporates the patch identified by commit id fc89e357feed5180ed1ab5eb9cb330578f025539. Users of older releases must upgrade to mitigate the risk.
Risk and Exploitability
The CVSS score of 6.9 indicates that the vulnerability is moderate but significant. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, yet the exploit has been made public and can be leveraged remotely. Attackers can gain unauthenticated access by manipulating the state parameter in the GitHub OAuth flow, leading to potential data exposure or control over the affected deployment.
OpenCVE Enrichment