CVE 9.4 CRITICAL

Coolify Stored Cross-Site Scripting (XSS) in Project Name Field_CVE-2025-34157

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the admin’s browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.

Basic Information

ID CVE-2025-34157
Source VulnCheck
Published Aug 27, 2025 at 16:48
Modified Aug 27, 2025 at 17:47

Affected Product

Vendor coolLabs Technologies
Product Coolify
Version *
Affected Versions coolLabs Technologies Coolify *

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.