Impact
The vulnerability is an OS command injection (CWE‑78) that occurs when user‑controlled persistent volume names are directly inserted into shell commands executed on managed servers. An authenticated member who can specify a volume name can include shell metacharacters, causing arbitrary code to run with root privileges when the volume operation is triggered. This flaw allows a full compromise of the affected managed server.
Affected Systems
Any installation of Coolify from coollabsio running a version older than 4.0.0‑beta.471 is vulnerable. The fix was introduced in the 4.0.0‑beta.471 release of the Coolify product.
Risk and Exploitability
The likely attack vector is via the managed server’s volume‑management interface; the attacker must have authenticated access and then trigger a volume operation containing malicious input. The CVSS score of 8.8 indicates high severity while the EPSS of < 1% suggests a low probability of exploitation in the wild. Because the flaw is reachable through normal UI actions and requires only authenticated credentials, environments that allow regular users to perform volume operations remain at significant risk of exploitation.
OpenCVE Enrichment