Impact
The flaw permits an authenticated user with application deployment write permissions to inject arbitrary shell commands into the deployment process, which are executed with the privileges of the deployment service. The injection also allows exfiltration of sensitive environment variables that are recorded in deployment logs, enabling attackers to obtain secrets such as passwords and API keys. This is an OS command injection weakness classified as CWE-78.
Affected Systems
The vulnerability affects all installations of Coolify provided by coollabsio prior to version 4.0.0-beta.469. Any instance running a vulnerable version can be exploited by users who possess application‑write deployment rights.
Risk and Exploitability
The CVSS score of 9.9 marks the issue as critical, while the EPSS score of 3% indicates a low but non‑zero chance of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. Full control of the host can be achieved if an attacker has legitimate deployment access, making the combination of an authentication requirement and remote command injection a high‑risk scenario.
OpenCVE Enrichment