CVE-2025-22609
CVSS 3.1 Score 10 of 10 (high)
Details
Summary
CVE-2025-22609 is a vulnerability affecting the Coolify open-source server management tool. Prior to version 4.0.0-beta.361, the software failed to implement proper authorization checks. This oversight enabled any authenticated user on a Coolify instance to attach another user's private key to their own server. If an attacker's target server's IP/domain, port (commonly 22), and user (often root) matched the configuration of the attached key, the attacker could exploit this vulnerability and execute arbitrary commands on the victim's server using the Terminal feature. The issue has been resolved in version 4.0.0-beta.361 of Coolify.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.