CRITICAL🇵🇱 Wersja polska

CVE-2025-59158

CVSS 9.4v4.0pub. 2026-01-05upd. 2026-01-12

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator later attempts to delete the project or its associated resource, the payload automatically executes in the admin’s browser context. Version 4.0.0-beta.420.7 contains a patch for the issue.

🤖 AI Analysis
How it works

An attacker with a role such as 'member' creates a project by giving it a name containing embedded JavaScript code. The application does not properly sanitize this name, which is a coding error (CWE-116) leading to stored XSS (CWE-79). When an administrator attempts to delete the project or an associated resource, the payload automatically executes in the context of the admin's browser, hijacking their session or performing actions on their behalf.

Impact

An attacker can execute arbitrary JavaScript code in the context of the administrator's session, which may lead to administrator account takeover, theft of authentication credentials, or execution of unauthorized operations on the managed infrastructure.

Mitigation & patch

Update Coolify to version 4.0.0-beta.420.7 or later, which contains a patch eliminating the vulnerability.

Who is affected

Coolify (Coollabs) in versions up to v4.0.0-beta.420.6 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Coollabs Coolify

    APP
    Coollabs
    4.0.0< 4.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-64419CRITICAL9.6PL ✓same product

Command injection w Coolify via docker-compose.yaml — RCE jako root

CVE-2025-64420CRITICAL9.9PL ✓same product

Coolify: nieuprawniony dostęp do prywatnego klucza SSH użytkownika root

CVE-2025-59156CRITICAL9.4PL ✓same product

RCE w Coolify — command injection w konfiguracji Docker Compose

CVE-2025-59157CRITICAL9.9PL ✓same product

Command injection w polu Git Repository w Coolify

CVE-2025-64424CRITICAL9.4PL ✓same product

Command injection w Coolify — wykonanie poleceń jako root przez użytkownika