SECURITYHIGHCVE-2026-100746

Coolify GitHub App Setup Handler Auth Bypass (CVE-2026-100746)

A missing-auth flaw in Coolify's GitHub App redirect handler lets remote attackers manipulate the state parameter to bypass auth.

Dylan H.

Security Team

September 27, 2026
4 min read
Coolify GitHub App Setup Handler Auth Bypass (CVE-2026-100746)

Affected Products

  • coollabsio Coolify, up to and including 4.1.0

Executive Summary

A missing authentication vulnerability (CVE-2026-100746) has been disclosed in Coolify, the popular open-source self-hosted PaaS platform. The flaw resides in the Github::redirect function that backs the /webhooks/source/github/redirect endpoint — Coolify's GitHub App Setup Handler — where manipulation of the state request argument allows a remote, unauthenticated attacker to bypass the authentication check that is supposed to gate this critical function. A public proof-of-concept exploit is already circulating.

CVSS Score: 7.3 (High, CVSS 3.1) — a companion CVSS 4.0 score of 5.5 is also published.


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-100746
CVSS Score7.3 (High), CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
TypeMissing Authentication for Critical Function (CWE-306, also mapped to CWE-287)
Affected ComponentGitHub App Setup Handler — Github::redirect
Affected Endpoint/webhooks/source/github/redirect
Vulnerable Parameterstate
Attack VectorNetwork
Privileges RequiredNone
Public ExploitYes — PoC published in a public GitHub repository
Confirmed In-the-Wild ExploitationNot reported as of publication
Published2026-09-27

Affected Products

ProductAffected VersionsFixed Version
coollabsio CoolifyUp to and including 4.1.04.1.1 (patch commit fc89e357feed5180ed1ab5eb9cb330578f025539)

Technical Details

Root Cause

Coolify's GitHub App onboarding flow uses a redirect handler to complete the OAuth-style setup exchange with GitHub. That handler is expected to validate the state value it receives before trusting the redirect and proceeding with the authenticated setup action. In the vulnerable versions, the Github::redirect function does not properly enforce this check, meaning the function that should only be reachable as part of a legitimate, already-authenticated setup flow can instead be reached and manipulated directly by an unauthenticated party.

Attack Chain

1. Attacker identifies a Coolify instance exposing the GitHub App
   Setup Handler at /webhooks/source/github/redirect
 
2. Attacker crafts a request with a manipulated `state` parameter,
   bypassing the authentication check the handler is meant to enforce
 
3. The handler processes the request as if it belonged to a
   legitimate, already-authenticated GitHub App setup flow
 
4. Depending on how the instance's GitHub integration is configured,
   this can expose or hijack the source-control connection Coolify
   relies on to pull and deploy application code

Impact Assessment

Impact AreaDescription
Authentication BypassAttacker reaches a function meant to require an authenticated setup session
Source Control TrustCoolify's GitHub App integration underpins automated deploys — abuse of the setup flow risks that trust relationship
Self-Hosted ExposureCoolify instances are typically internet-facing to receive GitHub webhooks, widening the pool of reachable targets
Public Exploit AvailabilityA PoC is already public, lowering the bar for opportunistic scanning and exploitation

Recommendations

Immediate Actions

  1. Upgrade to Coolify 4.1.1 or later immediately — this is the only complete fix.
  2. Audit GitHub App integrations configured on any Coolify instance for unexpected changes to installation scope, webhook URLs, or repository access.
  3. Restrict network exposure of the Coolify management interface and webhook endpoints to trusted IP ranges where your GitHub App configuration allows it.
  4. Review Coolify and reverse-proxy access logs for requests to /webhooks/source/github/redirect with anomalous or repeated state values.

Detection

  • Look for unexpected GitHub App installation or reconfiguration events tied to your Coolify deployment.
  • Monitor for unauthorized changes to source repositories or deploy pipelines managed through Coolify following any suspicious webhook traffic.

References