CVE-2025-34157
Coolify Stored Cross-Site Scripting (XSS) in Project Name Field
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the adminβs browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.
| CWE | CWE-79 CWE-20 |
| Vendor | coollabs technologies |
| Product | coolify |
| Published | Aug 27, 2025 |
| Last Updated | May 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for coollabs technologies coolify
Be the first to know when new unknown vulnerabilities affecting coollabs technologies coolify are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
coolLabs Technologies / Coolify
* < 4.0.0.-beta.420.7
References
Credits
Mike G.A (Eyodav)