Impact
A missing authorization check on Coolify’s terminal websocket bootstrap routes enables a user who has only low‑privilege team access to connect to the terminal service and execute arbitrary commands on team servers. Because only authentication is verified, the attacker can bypass intended role constraints and run code on the backend system, exposing all confidential data and potentially compromising the integrity and availability of the infrastructure managed by Coolify.
Affected Systems
Coolify by Coollabs.io, all versions preceding 4.0.0‑beta.471. The vulnerability exists in the terminal websocket bootstrap component of the application and is addressed in the 4.0.0‑beta.471 release and later. Systems that expose terminal websockets without a proper terminal authorization check are within scope.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score of < 1% reflects a very low but non‑zero probability of exploitation, while the absence of a KEV listing suggests no publicly known exploits yet. The likely attack vector is via the web interface and requires only authenticated access with low‑privilege credentials. Once connected, the attacker can run arbitrary commands on the server, representing a major threat to the confidentiality, integrity, and availability of the infrastructure.
OpenCVE Enrichment