Missing Authorization in Coolify Affects Server Management Security
CVE-2025-22607
What is CVE-2025-22607?
Coolify, a self-hostable tool designed for managing servers, applications, and databases, has a vulnerability that allows authenticated users to access sensitive configuration details without proper authorization. Prior to version 4.0.0-beta.361, users could retrieve the details of any GitHub or GitLab configuration solely by knowing the UUID of the model. This flaw potentially exposes critical information, including the 'client id', 'client secret', and 'webhook secret', posing significant risks to the security of the integrated services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
coolify < 4.0.0-beta.361
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
