No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 27 Sep 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded. | |
| Title | coollabsio Coolify GitHub App Setup redirect missing authentication | |
| First Time appeared |
Coollabsio
Coollabsio coolify |
|
| Weaknesses | CWE-287 CWE-306 |
|
| CPEs | cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Coollabsio
Coollabsio coolify |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-27T03:30:18.973Z
Reserved: 2026-09-26T13:32:40.829Z
Link: CVE-2026-100746
No data.
Status : Received
Published: 2026-09-27T04:16:34.570
Modified: 2026-09-27T04:16:34.570
Link: CVE-2026-100746
No data.
OpenCVE Enrichment
Updated: 2026-09-27T05:30:17Z