Goal Reached Thanks to every supporter β€” we hit 100%!

Goal: 1000 CNY Β· Raised: 1000 CNY

100.0%

CVE-2025-22611 β€” AI Deep Analysis Summary

CVSS 10.0 Β· Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Coolify < 4.0.0-beta.361 has a critical **Authorization Bypass**. πŸ“‰ **Consequences**: Attackers can escalate privileges to **Owner** level, gaining full control over the platform and all hosted resources.…

Q2Root Cause? (CWE/Flaw)

πŸ›‘οΈ **CWE**: **CWE-862** (Missing Authorization). πŸ” **Flaw**: The application fails to verify if a user has the right permissions before executing actions.…

Q3Who is affected? (Versions/Components)

πŸ“¦ **Vendor**: coollabsio. πŸ“¦ **Product**: Coolify. πŸ“‰ **Affected Versions**: All versions **before 4.0.0-beta.361**. βœ… **Fixed In**: Version 4.0.0-beta.361 and later.

Q4What can hackers do? (Privileges/Data)

πŸ‘‘ **Privileges**: Escalate from any role to **Owner**. πŸ“‚ **Data Access**: Full read/write access to all projects, servers, and configurations.…

Q5Is exploitation threshold high? (Auth/Config)

⚠️ **Threshold**: **Low**. πŸšͺ **Auth Required**: Yes, the attacker must be an **authenticated user**. 🚫 **No Auth Bypass**: Does not require anonymous access. 🎯 **Ease**: **Low Complexity (AC:L)**.…

Q6Is there a public Exp? (PoC/Wild Exploitation)

🚫 **Public Exploit**: **No**. πŸ“ **PoC**: None listed in the advisory. 🌍 **Wild Exploitation**: Unconfirmed. However, the logic flaw is simple, so PoCs may emerge quickly.…

Q7How to self-check? (Features/Scanning)

πŸ” **Check**: Verify your Coolify version in the dashboard. πŸ“… **Date**: Published 2025-01-24. πŸ› οΈ **Scan**: Look for version **< 4.0.0-beta.361**.…

Q8Is it fixed officially? (Patch/Mitigation)

βœ… **Fixed**: **Yes**. πŸ“¦ **Patch**: Upgrade to **Coolify 4.0.0-beta.361** or newer. πŸ”— **Source**: Official GitHub Security Advisory (GHSA-9w72-9qww-qj6g). πŸ”„ **Action**: Immediate update recommended for all beta users.

Q9What if no patch? (Workaround)

πŸ›‘οΈ **Workaround**: If you cannot update immediately, **restrict user creation**. πŸ‘₯ **Limit Access**: Only allow trusted admins. πŸ”’ **Network**: Isolate the Coolify instance from untrusted networks.…

Q10Is it urgent? (Priority Suggestion)

πŸ”₯ **Urgency**: **CRITICAL**. 🚨 **Priority**: **P1**. ⚑ **Reason**: CVSS Vector shows **High** impact (C:H, I:H, A:H) and **Low** complexity. πŸ“’ **Action**: Patch immediately. This allows any user to become the owner.…