Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in Coolify, an open-source tool for managing servers and applications, that could allow a low-privilege user to execute malicious code within an administrator's browser. This occurs when an administrator interacts with a project created with a specially crafted name, potentially impacting the integrity of administrative operations. The primary concern is to verify if this specific technology is in use and assess any exposure.
- Malicious code execution via project names.
- Impacts administrative control of server management.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker with low-privilege access can create a new project using a name that contains malicious JavaScript code. This code will execute when an administrator attempts to delete the project or its related resources, potentially leading to broader system compromise.
- Authenticated, low-privilege user required.
- Triggered by project deletion action.
- Risk of administrator browser compromise.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could impact the Coolify application by allowing an authenticated user, even with a low-privilege role, to inject malicious JavaScript into a project name. This script could execute in the browser of an administrator when they interact with the project, potentially affecting their session or actions within the Coolify interface. No specific system data, user data, or PII is indicated as being at risk based on the provided context.
- Administrator sessions and actions within Coolify.
- Malicious script execution via project deletion.
- Compromised administrator actions within the tool.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts Coolify, a self-hosted server and application management tool. Ownership likely falls to the platform or infrastructure teams responsible for deploying and managing Coolify instances, in coordination with security teams for exposure assessment. The first practical step is to inventory all Coolify deployments, identify which are externally accessible, and then determine the responsible team for remediation.
- Platform or infrastructure teams own the issue.
- Verify external accessibility and business criticality.
- Plan remediation based on identified risk.