Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in Coolify, a server management tool, allows a low-privileged user to execute arbitrary commands on the host operating system by injecting malicious configurations during application deployment. This bypasses container isolation and can grant attackers root-level access.
- Allows code execution on host systems.
- Critical vulnerability could impact system integrity.
- Confirm relevance and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker with low-level access to Coolify can inject malicious code during application deployment. This allows them to modify Docker Compose configurations to mount the host's filesystem, enabling them to execute commands with root privileges on the underlying operating system and bypass container security.
- Network access, low-privileged user.
- Injecting malicious Docker Compose directives.
- Root-level command execution on host.
Live Threat
Current exploitation, exposure, and threat context
A low-privileged member could inject malicious Docker Compose directives during project creation or updates in Coolify. This could allow them to define a service that mounts the host's filesystem, potentially leading to root-level command execution on the host operating system and bypassing container isolation.
- Host OS and containerized services at risk.
- Attacker mounts host filesystem via malicious service.
- Root command execution, container escape possible.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Coolify application owner or the infrastructure team managing the self-hosted environment is likely responsible for addressing this vulnerability. The first practical step is to identify all instances of Coolify, confirm their network exposure and business criticality, and then coordinate remediation with the accountable owner.
- Application or infrastructure teams own the issue.
- Verify Coolify instances and their exposure.
- Plan and execute the upgrade to patched version.