Executive Summary
A missing authentication vulnerability (CVE-2026-100746) has been disclosed in Coolify, the popular open-source self-hosted PaaS platform. The flaw resides in the Github::redirect function that backs the /webhooks/source/github/redirect endpoint — Coolify's GitHub App Setup Handler — where manipulation of the state request argument allows a remote, unauthenticated attacker to bypass the authentication check that is supposed to gate this critical function. A public proof-of-concept exploit is already circulating.
CVSS Score: 7.3 (High, CVSS 3.1) — a companion CVSS 4.0 score of 5.5 is also published.
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-100746 |
| CVSS Score | 7.3 (High), CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| Type | Missing Authentication for Critical Function (CWE-306, also mapped to CWE-287) |
| Affected Component | GitHub App Setup Handler — Github::redirect |
| Affected Endpoint | /webhooks/source/github/redirect |
| Vulnerable Parameter | state |
| Attack Vector | Network |
| Privileges Required | None |
| Public Exploit | Yes — PoC published in a public GitHub repository |
| Confirmed In-the-Wild Exploitation | Not reported as of publication |
| Published | 2026-09-27 |
Affected Products
| Product | Affected Versions | Fixed Version |
|---|---|---|
| coollabsio Coolify | Up to and including 4.1.0 | 4.1.1 (patch commit fc89e357feed5180ed1ab5eb9cb330578f025539) |
Technical Details
Root Cause
Coolify's GitHub App onboarding flow uses a redirect handler to complete the OAuth-style setup exchange with GitHub. That handler is expected to validate the state value it receives before trusting the redirect and proceeding with the authenticated setup action. In the vulnerable versions, the Github::redirect function does not properly enforce this check, meaning the function that should only be reachable as part of a legitimate, already-authenticated setup flow can instead be reached and manipulated directly by an unauthenticated party.
Attack Chain
1. Attacker identifies a Coolify instance exposing the GitHub App
Setup Handler at /webhooks/source/github/redirect
2. Attacker crafts a request with a manipulated `state` parameter,
bypassing the authentication check the handler is meant to enforce
3. The handler processes the request as if it belonged to a
legitimate, already-authenticated GitHub App setup flow
4. Depending on how the instance's GitHub integration is configured,
this can expose or hijack the source-control connection Coolify
relies on to pull and deploy application codeImpact Assessment
| Impact Area | Description |
|---|---|
| Authentication Bypass | Attacker reaches a function meant to require an authenticated setup session |
| Source Control Trust | Coolify's GitHub App integration underpins automated deploys — abuse of the setup flow risks that trust relationship |
| Self-Hosted Exposure | Coolify instances are typically internet-facing to receive GitHub webhooks, widening the pool of reachable targets |
| Public Exploit Availability | A PoC is already public, lowering the bar for opportunistic scanning and exploitation |
Recommendations
Immediate Actions
- Upgrade to Coolify 4.1.1 or later immediately — this is the only complete fix.
- Audit GitHub App integrations configured on any Coolify instance for unexpected changes to installation scope, webhook URLs, or repository access.
- Restrict network exposure of the Coolify management interface and webhook endpoints to trusted IP ranges where your GitHub App configuration allows it.
- Review Coolify and reverse-proxy access logs for requests to
/webhooks/source/github/redirectwith anomalous or repeatedstatevalues.
Detection
- Look for unexpected GitHub App installation or reconfiguration events tied to your Coolify deployment.
- Monitor for unauthorized changes to source repositories or deploy pipelines managed through Coolify following any suspicious webhook traffic.