Impact
The vulnerability is a command injection flaw in the CA Certificate management feature of Coolify prior to 4.0.0‑beta.464. An attacker who has authenticated access can embed and execute arbitrary shell commands, which are run with the privileges of the configured SSH user on the managed server. If that SSH user is root or a member of the docker group, the attacker effectively gains full control over the server and any containers running on it. This flaw is a classic example of CWE‑78.
Affected Systems
The affected product is Coollabsio Coolify, any version before 4.0.0‑beta.464. Users must consider that only authenticated users can trigger the injection, so any user with normal access to the Coolify UI has the ability to exploit the issue. The attack is confined to the server that the Coolify installation manages; it does not affect other nodes.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity. The vulnerability is not listed in CISA KEV and the EPSS score is not available, but given the nature of the flaw and the large user base of open‑source self‑hosted tooling, the likelihood of exploitation can be considered moderate to high. The attack vector is authenticated remote, requiring the attacker to be able to log into Coolify. Once authenticated, exploit is straightforward and does not require additional conditions; the injection leads to arbitrary command execution as the specified SSH user.
OpenCVE Enrichment