Impact
An access control flaw in Coolify’s terminal WebSocket bootstrap routes allows an authenticated user to invoke terminal commands on resources outside their authorized scope, therefore enabling remote code execution. The exploit is possible because the expected authorization middleware is not applied, allowing the user to bypass the platform’s scope checks. This directly threatens system integrity and confidentiality for any’s control, as the flaw is a missing authorization check (CWE‑863).
Affected Systems
The affected product is Coolify from Coollabsio. All releases prior to 4.0.0‑beta.471 are vulnerable. Coolify is an open‑source, self‑hosted tool for managing servers, applications, and databases, and the vulnerability resides in its terminal WebSocket bootstrap functionality.
Risk and Exploitability
The CVSS score of 9.9 classifies the severe potential impact when exploited. Although the EPSS score is listed as <1%, indicating a very low likelihood of exploitation at present, the high severity remains a critical risk for any affected installation. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is an authenticated user accessing the web interface to open the vulnerable WebSocket endpoint; from there, the attacker can execute arbitrary commands on resources outside their permitted scope.
OpenCVE Enrichment