Impact
DatabaseBackupJob in Coolify builds shell commands with user‑controlled database credentials and MongoDB collection exclusion names without proper escaping. This allows an authenticated database‑manager to inject arbitrary shell commands into the backup process, leading to full remote code execution with the privileges of the user running the job. The flaw is a command‑injection vulnerability (CWE‑78) and can compromise confidentiality, integrity, and availability of the managed host.
Affected Systems
The affected product is CoollabsIO Coolify. Versions earlier than 4.0.0‑beta.471 are vulnerable.
Risk and Exploitability
The CVSS score of 3.3 indicates EPSS score of <1% suggests a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user with database‑management permissions in Coolify, but once authenticated, the attacker can execute commands on the host machine.
OpenCVE Enrichment