coolLabs Coolify是coolLabs团队开源的一个开源和自托管的 Heroku/Netlify/Vercel 替代品。 CoolLabs Coolify 4.0.0-beta.464之前版本存在授权问题漏洞,该漏洞源于 在提供可选的uuid查询参数时绕过团队范围限制,可能导致任何经过身份验证的API用户枚举其他团队的应用程序域名(FQDN)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.464 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.464 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27957 | 8.8 HIGH | Coolify: Authenticated RCE via command injection in CA certificate management feature |
| CVE-2026-27955 | 6.6 MEDIUM | Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()` |
| CVE-2026-27883 | 5.0 MEDIUM | Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure |
| CVE-2026-27881 | 5.0 MEDIUM | Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} ( |
| CVE-2026-27882 | 4.8 MEDIUM | Coolify: Timing Attack in GitLab Webhook Token Validation |
No comments yet