Impact
A regression in Coolify’s SHELL_SAFE_COMMAND_PATTERN allowed ampersand characters to be interpreted as command separators in custom Docker Compose build, start, and pre/post‑deployment command fields. authenticated team member to inject on the host, granting unrestricted root access.
Affected Systems
Coollabsio’s Coolify product between versions 4.0.0‑beta.471 and 4.0.0‑beta.473 is affected. Any authenticated user with permission to edit the Docker Compose build, start. The issue is fixed in version 4.0.0‑beta.474, which restores fields to the highest‑privileged users.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, while the EPSS score of less than 1 % indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authentication and write access to the impacted fields, limiting the threat to internal users with sufficient privileges, yet providing full host control once successful.
OpenCVE Enrichment