CVE-2026-100746: coollabsio Coolify GitHub App Setup redirect missing authentication
A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
coollabsio Coolifyto a version that resolves this vulnerability.Fixed in 4.1.1Patch fc89e357feed5180ed1ab5eb9cb330578f025539
Event History
Frequently Asked Questions
Which Coolify deployments are affected?
Coolify versions up to and including 4.1.0 are affected where the GitHub App Setup Handler is present. Version 4.1.1 mitigates the issue.
What does an attacker need to exploit this issue?
The attack can be performed remotely by manipulating the state argument handled by the GitHub App Setup redirect endpoint. No privileges or user interaction are indicated in the provided severity vector.
Is public exploit code available?
Yes. The exploit has been made public and could be used.
What should be done if this is identified in an environment?
Upgrade the affected Coolify component to version 4.1.1. The mitigating patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539.