Impact
The vulnerability in Coolify’s deployment job permits an attacker to modify health check configuration fields. By embedding unsanitized values for the health check host, method, and path directly into shell commands, the attacker can execute code inside deployment containers. This vulnerability is an instance of CWE‑78, an OS Command Injection flaw.
Affected Systems
The affected product is Coolify by coollabsio. All releases prior‑beta.469 are vulnerable, regardless of specific minor version numbers.
Risk and Exploitability
The CVSS score of 8.8 highlights a high severity. The EPSS score is less than 1%, indicating a low probability of exploitation in the current environment, but the lack of a KEV listing does not diminish the risk; attackers can exploit the flaw by creating or editing health check settings for any application they manage. Successful exploitation yields remote code execution within the affected container, compromising confidentiality, integrity, and availability of the application and host.
OpenCVE Enrichment