PT-2026-1314 · Coolify · Coolify

CVE-2025-59158

·

Publicado

2026-01-05

·

Atualizado

2026-01-12

CVSS v4.0

9.4

Crítica

VetorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.420.7
Description Coolify is a self-hostable tool for managing servers, applications, and databases. A stored cross-site scripting (XSS) issue exists in the project creation workflow. An authenticated user with low privileges can create a project with a malicious name containing JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the administrator’s browser. The vulnerable component is the project creation workflow, where the project name is not properly sanitized. The API endpoint used for project creation is not specified. The vulnerable parameter is the project name.
Recommendations Update to Coolify version 4.0.0-beta.420.7 or later.

Exploit

Correção

Improper Encoding or Escaping of Output

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-59158
GHSA-H52R-JXV9-9VHF

Produtos afetados

Coolify