Impact
The vulnerability is that Coolify’s Sanctum API tokens do not have an expiration time. Consequently, a token that is leaked, exposed or otherwise compromised remains valid for an indefinite period until it is revoked manually. This allows an attacker who obtains any valid token to maintain continuous unauthorised access to the affected authorised operations. The weakness is identified as CWE‑613, a failure to enforce correct authorization or token expiry.
Affected Systems
Deployments of Coolify from Coollabs.io that are running any version earlier than 4.0.0. in, so any installation that has not applied the update bears the risk.
Risk and Exploitability
The CVSS score of 3.1 places the vulnerability in the low‑severity range, but because the token never expires, the impact of a successful compromise is permanent. The EPSS score of <1% indicates a very low yet non‑zero probability that an attacker will exploit this weakness. The vulnerability is not listed in CISA’s KEV catalogue, suggesting no known widespread exploitation. The likely attack vector involves the accidental leakage or insecure handling of the token, after which an attacker can use it without further authentication steps.
OpenCVE Enrichment