PT-2025-4597 · Coolify · Coolify

Angelej

·

Published

2025-01-24

·

Updated

2025-02-05

·

CVE-2025-22611

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.361
Description The issue allows any authenticated user to escalate their or other team members' privileges to any role, including the owner role. This also enables the attacker to kick every other member out of the team, including admins and owners, and access the Terminal feature to execute remote commands.
Recommendations Coolify versions prior to 4.0.0-beta.361 should be updated to version 4.0.0-beta.361 to fix the issue.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-22611
GHSA-9W72-9QWW-QJ6G

Affected Products

Coolify