Authorization Flaw in Coolify Affects Server Management Tool
CVE-2025-22608
6.5MEDIUM
What is CVE-2025-22608?
Coolify, an open-source tool for managing servers, applications, and databases, suffers from an authorization vulnerability prior to version 4.0.0-beta.361. This flaw permits authenticated users to revoke any team invitations by simply providing a predictable and incrementing ID. Consequently, this could lead to a Denial-of-Service attack, disrupting team operations within a Coolify instance. Users are advised to upgrade to 4.0.0-beta.361 or later to mitigate this vulnerability.
Affected Version(s)
coolify < 4.0.0-beta.361