Impact
The vulnerability in Coolify’s deployment job permits an attacker to modify health check configuration fields. By embedding unsanitized values for the health_check_host, health_check_method, and health_check_path directly into shell commands, the attacker can execute code inside deployment containers. Based on the description, it is inferred that the health_check_path parameter serves as the query path for command injection. This flaw is an instance of CWE‑78, an OS Command Injection vulnerability. Successful exploitation allows remote code execution within the container, compromising confidentiality, integrity, and availability of both the application and the host system.
Affected Systems
The affected product is Coolify by coollabsio. All releases prior‑beta.469 are vulnerable, regardless of specific minor version numbers.
Risk and Exploitability
The CVSS score of 8.8 highlights a high severity. The EPSS score is less than 1%, indicating a low probability of exploitation in the current environment, but the lack of a KEV listing does not diminish the risk; attackers can exploit the flaw by creating or editing health check settings for any application they manage. Successful exploitation yields remote code execution within the affected container, compromising confidentiality, integrity, and availability of the application and host.
OpenCVE Enrichment