PT-2025-34899 · Coolify · Coolify

Mike G.A

·

Published

2025-08-27

·

Updated

2025-08-28

·

CVE-2025-34157

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Coolify versions prior to v4.0.0-beta.420.6
Description: Coolify is susceptible to a stored cross-site scripting (XSS) attack within the project creation workflow. An authenticated user possessing low privileges can create a project utilizing a maliciously crafted name that incorporates embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload is executed within the administrator’s browser context, potentially leading to a full compromise of the Coolify instance. This compromise may include the theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.
Recommendations: Update to Coolify version 4.0.0-beta.420.6 or later.

Exploit

Fix

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34157

Affected Products

Coolify