Executive brief
Coolify, an open-source platform for managing servers and applications, contains a security flaw that allows users to view logs belonging to other teams. By providing a specific identifier for a resource they do not own, an authenticated user can bypass privacy boundaries to access sensitive information. This could lead to the exposure of application secrets, tokens, or other private data contained within system logs.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Logs::mount() component of Coolify. The application performs resource lookups using UUIDs provided in request parameters but fails to verify that the requested resource belongs to the authenticated user's team. An attacker with a valid account can access logs for applications, services, or databases owned by other tenants by supplying the target resource's UUID. This vulnerability is classified under CWE-639 and was addressed in version 4.0.0-beta.466 by implementing team-scoped queries (ownedByCurrentTeam()) for resource resolution.
Affected products
- coollabsio Coolify < 4.0.0-beta.466
Timeline
- 2026-03-04: disclosed: Vulnerability reported by Xyptonize
- 2026-03-10: patched: Fix committed to repository
- 2026-03-11: patched: Version 4.0.0-beta.466 released
- 2026-07-07: advisory: GitHub Advisory and CVE published