Impact
The regression in Coolify’s SHELL_SAFE_COMMAND_PATTERN permitted ampersand characters to be treated as command separators within custom Docker Compose build, start, and pre/post‑deployment command fields. An authenticated team member who can edit these fields can thus inject arbitrary shell commands that execute on the host machine, providing an attacker with full host‑level control (OS Command Injection, CWE‑78).
Affected Systems
Coollabsio’s Coolify product, specifically versions 4.0.0-beta.471 through 4.0.0-beta.473, is impacted. Version 4.0.0-beta.474 addresses the regression by enforcing stricter command‑pattern validation.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1 % suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires valid authentication and write access to the affected command fields, limiting the risk to users with sufficient privileges. Once achieved, the attacker can execute commands with host root privileges.
OpenCVE Enrichment