Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator later attempts to delete the project or its associated resource, the payload automatically executes in the admin’s browser context. Version 4.0.0-beta.420.7 contains a patch for the issue.
An attacker with a role such as 'member' creates a project by giving it a name containing embedded JavaScript code. The application does not properly sanitize this name, which is a coding error (CWE-116) leading to stored XSS (CWE-79). When an administrator attempts to delete the project or an associated resource, the payload automatically executes in the context of the admin's browser, hijacking their session or performing actions on their behalf.
An attacker can execute arbitrary JavaScript code in the context of the administrator's session, which may lead to administrator account takeover, theft of authentication credentials, or execution of unauthorized operations on the managed infrastructure.
Update Coolify to version 4.0.0-beta.420.7 or later, which contains a patch eliminating the vulnerability.
Coolify (Coollabs) in versions up to v4.0.0-beta.420.6 inclusive
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCoollabs Coolify
APPCoollabs4.0.0< 4.0.0
Related vulnerabilities
Command injection w Coolify via docker-compose.yaml — RCE jako root
Coolify: nieuprawniony dostęp do prywatnego klucza SSH użytkownika root
RCE w Coolify — command injection w konfiguracji Docker Compose
Command injection w polu Git Repository w Coolify
Command injection w Coolify — wykonanie poleceń jako root przez użytkownika