PT-2025-4595 · Coolify · Coolify
Angelej
·
Published
2025-01-24
·
Updated
2025-02-05
·
CVE-2025-22609
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Coolify versions prior to 4.0.0-beta.361
Description
The issue allows any authenticated user to attach any existing private key on a Coolify instance to their own server. If the server configuration of IP/domain, port, and user matches with the victim's server configuration, then the attacker can use the "Terminal" feature and execute arbitrary commands on the victim's server. This potentially grants root access to other servers.
Recommendations
Coolify versions prior to 4.0.0-beta.361: Update to version 4.0.0-beta.361 or later to fix the issue. As a temporary workaround, consider restricting access to the
Terminal feature until a patch is available. Additionally, review server configurations to ensure that IP/domain, port, and user settings do not match with other servers, minimizing the risk of exploitation.Exploit
Fix
LPE
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coolify