coolLabs Coolify是coolLabs团队开源的一个开源和自托管的 Heroku/Netlify/Vercel 替代品。 CoolLabs Coolify 4.0.0-beta.464之前版本存在授权问题漏洞,该漏洞源于在DeployController.php中检索部署详细信息时未验证部署是否属于已认证用户的团队,导致任何已认证的API用户可以通过提供有效的部署UUID读取其他团队的部署记录。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.464 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.464 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27957 | 8.8 HIGH | Coolify: Authenticated RCE via command injection in CA certificate management feature |
| CVE-2026-27955 | 6.6 MEDIUM | Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()` |
| CVE-2026-27883 | 5.0 MEDIUM | Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure |
| CVE-2026-27882 | 4.8 MEDIUM | Coolify: Timing Attack in GitLab Webhook Token Validation |
| CVE-2026-27956 | 4.3 MEDIUM | Coolify: Cross-team application domain enumeration via domains_by_server endpoint |
No comments yet