CVE-2025-22612
CVSS 3.1 Score 10 of 10 (high)
Details
Summary
CVE-2025-22612 is a vulnerability affecting the open-source Coolify tool, used for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the software lacked sufficient authorization checks, enabling authenticated users to retrieve any existing private keys in plain text. If an attacker's server configuration matches the victim's (IP/domain, port, and user, often with root access), they can execute arbitrary commands on the remote server, potentially leading to significant security compromises. The vulnerability is addressed in version 4.0.0-beta.374 through proper authorization checks and key handling improvements.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.