Vulnerabilities in coollabsio
71 resultsVexday analysis
A Coollabs acumula 71 vulnerabilidades no histórico, com 46 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas. Embora nenhuma esteja sob exploração ativa no momento, 19 são classificadas como críticas, predominantemente relacionadas a injeção de comandos (CWE-78), o que representa risco significativo se explorado. A concentração recente de divulgações requer monitoramento atento e priorização de patches críticos.
CVE-2026-41899MEDIUMCoolify unauthenticated feedback endpoint allows Discord webhook abuseEPSS 0.3%CVE-2026-34037CRITICALCross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()EPSS 0.3%CVE-2025-22606HIGHCoolify Command Injection Vulnerability in Project NameEPSS 0.3%CVE-2025-64422MEDIUMRate-limit bypass on login via X-Forwarded-Host headerEPSS 0.3%CVE-2025-64421HIGHCoolify has a privilege escalation - low privileged user can invite themselves as an admin userEPSS 0.3%CVE-2025-59955MEDIUMCoolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpointEPSS 0.3%CVE-2026-42147MEDIUMCoolify: SSRF via S3 Storage Endpoint in testConnection()EPSS 0.3%CVE-2026-57498CRITICALCoolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and destination_uuid — Deploy to Other Teams' ServersEPSS 0.3%CVE-2026-42145LOWCoolify: File Upload Without Type or Size Validation in Database Backup RestoreEPSS 0.3%CVE-2026-34044HIGHCoolify: Cross-team IDOR in logs component (resource lookup not team-scoped)EPSS 0.2%CVE-2026-41896HIGHCoolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null SecretEPSS 0.2%CVE-2025-24025LOWCoolify Vulnerable to Reflected XSS on Tag SearchEPSS 0.2%CVE-2026-27955MEDIUMCoolify: Command Injection via Single-Quote Breakout in `executeInDocker()`EPSS 0.2%CVE-2026-34149LOWCoolify: Authenticated Host-Level RCE via Unescaped Database Credentials in Backup JobsEPSS 0.2%CVE-2026-34050MEDIUMCoolify Settings/Updates Livewire component missing instance administrator authorizationEPSS 0.2%CVE-2026-32718MEDIUMCoolify read-scoped API tokens can perform state-changing validation operationsEPSS 0.2%CVE-2026-27883MEDIUMCoolify: IDOR in Deployment API - Cross-Team Deployment Information DisclosureEPSS 0.2%CVE-2026-34592HIGHCoolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH Keys and InfrastructureEPSS 0.2%CVE-2026-15507MEDIUMcoollabsio Coolify Policy Policies authorizationEPSS 0.2%CVE-2026-34167MEDIUMCoolify: Cross-tenant activity log disclosure via unlocked Livewire property in ActivityMonitorEPSS 0.2%