Sceawere
Vulnerability Detail
CVE-2026-100746UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Coolify GitHub OAuth Authentication Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 1d ago
- Vendor
- coollabsio
- Product
- Coolify
- Attack Type
- Missing Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-27T04:16:34.570Z",
"pubdate": "2026-09-27T04:16:34.570Z",
"executiveSummary": "A critical authentication bypass vulnerability exists in the GitHub App Setup Handler of Coolify, affecting versions up to 4.1.0.\nThe vulnerability originates from improper handling of the 'state' parameter within the Github::redirect function, leading to a failure in validating the integrity of the OAuth callback process.\nThis flaw allows remote, unauthenticated attackers to manipulate the authentication flow, potentially leading to unauthorized access or identity impersonation within the application context.\nGiven that the exploit is public, the risk is severe, as it facilitates remote exploitation without requiring prior authentication or credentials.\nImmediate upgrade to version 4.1.1 is required to remediate this security deficiency and restore the integrity of the GitHub authentication integration.",
"technicalDetails": "The vulnerability is located in the GitHub App Setup Handler component, specifically within the Github::redirect function found at /webhooks/source/github/redirect.\nThe root cause of this vulnerability is a deficiency in the validation logic for the 'state' parameter, which is a security token used in OAuth 2.0 flows to maintain state between the authorization request and the callback response, thereby preventing Cross-Site Request Forgery (CSRF) and injection attacks.\nIn the affected versions of Coolify, the implementation fails to verify that the 'state' parameter returned by the GitHub callback matches the 'state' parameter originally generated by the application. By manipulating this argument, an attacker can bypass the intended authentication sequence.\nThe attack flow proceeds as follows: An unauthenticated remote attacker initiates a crafted request targeting the GitHub callback endpoint. By supplying a malicious or manipulated 'state' parameter that bypasses the integrity check, the attacker forces the application to treat the incoming callback as a valid, authorized session initiation.\nThis allows the attacker to circumvent the standard OAuth handshake requirements, effectively performing actions or assuming sessions that should only be available to authorized users who have successfully completed the GitHub authentication process.\nBecause the function fails to adequately bind the callback response to the initial request, the application is susceptible to remote exploitation via the web interface. The lack of strict verification means the server does not differentiate between a legitimate user-initiated callback and a maliciously constructed payload.\nThe post-exploitation impact includes unauthorized access to the application via the GitHub provider, potentially allowing an attacker to link or manipulate GitHub-based resources or configurations within the Coolify environment.\nThis vulnerability is identified by patch commit fc89e357feed5180ed1ab5eb9cb330578f025539, which likely implements proper session state persistence and strict comparison logic to ensure the 'state' parameter remains immutable and verified throughout the authentication cycle."
}