A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded.
PUBLISHED5.2ApplicationCWE-306CWE-287x_open-source
coollabsio Coolify GitHub App Setup redirect missing authentication
Problem type
Affected products
coollabsio
Coolify
4.0 - AFFECTED
4.1.0 - AFFECTED
4.1.1 - UNAFFECTED
References
VDB-410617 | coollabsio Coolify GitHub App Setup redirect missing authentication
https://vuldb.com/vuln/410617
VDB-410617 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/410617/cti
CVE-2026-100746 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-100746
Submit #897404 | coollabsio Coolify 4.1.1 Missing Authentication
https://vuldb.com/submit/897404
github.com
https://github.com/lakshayyverma/CVE-Discovery/blob/main/coolify-unauth-secret-overwrite-github-app-redirect.7z
github.com
https://github.com/coollabsio/coolify/pull/10362
github.com
https://github.com/coollabsio/coolify/commit/fc89e357feed5180ed1ab5eb9cb330578f025539
github.com
https://github.com/coollabsio/coolify/releases/tag/v4.1.1
github.com
https://github.com/coollabsio/coolify/
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-100746Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-100746",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-09-27T03:30:18.973Z",
"dateReserved": "2026-09-26T13:32:40.829Z",
"datePublished": "2026-09-27T03:30:18.973Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-09-27T03:30:18.973Z"
},
"title": "coollabsio Coolify GitHub App Setup redirect missing authentication",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded."
}
],
"affected": [
{
"vendor": "coollabsio",
"product": "Coolify",
"cpes": [
"cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:*"
],
"modules": [
"GitHub App Setup Handler"
],
"versions": [
{
"version": "4.0",
"status": "affected"
},
{
"version": "4.1.0",
"status": "affected"
},
{
"version": "4.1.1",
"status": "unaffected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Missing Authentication",
"cweId": "CWE-306",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Improper Authentication",
"cweId": "CWE-287",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/410617",
"name": "VDB-410617 | coollabsio Coolify GitHub App Setup redirect missing authentication",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/410617/cti",
"name": "VDB-410617 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-100746",
"name": "CVE-2026-100746 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/897404",
"name": "Submit #897404 | coollabsio Coolify 4.1.1 Missing Authentication",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/lakshayyverma/CVE-Discovery/blob/main/coolify-unauth-secret-overwrite-github-app-redirect.7z",
"tags": [
"exploit"
]
},
{
"url": "https://github.com/coollabsio/coolify/pull/10362",
"tags": [
"issue-tracking",
"patch"
]
},
{
"url": "https://github.com/coollabsio/coolify/commit/fc89e357feed5180ed1ab5eb9cb330578f025539",
"tags": [
"patch"
]
},
{
"url": "https://github.com/coollabsio/coolify/releases/tag/v4.1.1",
"tags": [
"patch"
]
},
{
"url": "https://github.com/coollabsio/coolify/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-09-26T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-09-26T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-09-26T15:37:51.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "lakshay12311 (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_open-source"
]
}
}
}