CVE-2026-100746 | coollabsio Coolify up to 4.1.0 GitHub App Setup redirect Github::redirect state missing authentication
A vulnerability labeled as critical has been found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication.
This vulnerability is identified as CVE-2026-100746. The attack can be executed remotely. Additionally, an exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More