PT-2025-34899 · Coolify · Coolify
Mike G.A
·
Published
2025-08-27
·
Updated
2025-08-28
·
CVE-2025-34157
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions:
Coolify versions prior to v4.0.0-beta.420.6
Description:
Coolify is susceptible to a stored cross-site scripting (XSS) attack within the project creation workflow. An authenticated user possessing low privileges can create a project utilizing a maliciously crafted name that incorporates embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload is executed within the administrator’s browser context, potentially leading to a full compromise of the Coolify instance. This compromise may include the theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.
Recommendations:
Update to Coolify version 4.0.0-beta.420.6 or later.
Exploit
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coolify