CVE-2025-59158
Published: Jan 5, 2026Modified: Jan 12, 2026
9.4
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security-advisories@github.com (Secondary)
8.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: NVD
Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator later attempts to delete the project or its associated resource, the payload automatically executes in the admin’s browser context. Version 4.0.0-beta.420.7 contains a patch for the issue.
Affected (408)
Configuration A408 vulnerable
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.0.0 | |
| Version 4.0.0 beta100 | |
| Version 4.0.0 beta101 | |
| Version 4.0.0 beta102 | |
| Version 4.0.0 beta103 | |
| Version 4.0.0 beta104 | |
| Version 4.0.0 beta105 | |
| Version 4.0.0 beta106 | |
| Version 4.0.0 beta107 | |
| Version 4.0.0 beta108 | |
| Version 4.0.0 beta109 | |
| Version 4.0.0 beta110 | |
| Version 4.0.0 beta111 | |
| Version 4.0.0 beta112 | |
| Version 4.0.0 beta113 | |
| Version 4.0.0 beta114 | |
| Version 4.0.0 beta115 | |
| Version 4.0.0 beta116 | |
| Version 4.0.0 beta117 | |
| Version 4.0.0 beta118 | |
| Version 4.0.0 beta119 | |
| Version 4.0.0 beta120 | |
| Version 4.0.0 beta121 | |
| Version 4.0.0 beta122 | |
| Version 4.0.0 beta123 | |
| Version 4.0.0 beta124 | |
| Version 4.0.0 beta125 | |
| Version 4.0.0 beta126 | |
| Version 4.0.0 beta127 | |
| Version 4.0.0 beta128 | |
| Version 4.0.0 beta129 | |
| Version 4.0.0 beta130 | |
| Version 4.0.0 beta131 | |
| Version 4.0.0 beta132 | |
| Version 4.0.0 beta133 | |
| Version 4.0.0 beta134 | |
| Version 4.0.0 beta135 | |
| Version 4.0.0 beta136 | |
| Version 4.0.0 beta137 | |
| Version 4.0.0 beta138 | |
| Version 4.0.0 beta139 | |
| Version 4.0.0 beta140 | |
| Version 4.0.0 beta141 | |
| Version 4.0.0 beta142 | |
| Version 4.0.0 beta143 | |
| Version 4.0.0 beta144 | |
| Version 4.0.0 beta145 | |
| Version 4.0.0 beta146 | |
| Version 4.0.0 beta147 | |
| Version 4.0.0 beta148 | |
| Version 4.0.0 beta149 | |
| Version 4.0.0 beta150 | |
| Version 4.0.0 beta151 | |
| Version 4.0.0 beta152 | |
| Version 4.0.0 beta153 | |
| Version 4.0.0 beta154 | |
| Version 4.0.0 beta155 | |
| Version 4.0.0 beta156 | |
| Version 4.0.0 beta157 | |
| Version 4.0.0 beta158 | |
| Version 4.0.0 beta159 | |
| Version 4.0.0 beta160 | |
| Version 4.0.0 beta161 | |
| Version 4.0.0 beta162 | |
| Version 4.0.0 beta163 | |
| Version 4.0.0 beta164 | |
| Version 4.0.0 beta165 | |
| Version 4.0.0 beta166 | |
| Version 4.0.0 beta167 | |
| Version 4.0.0 beta168 | |
| Version 4.0.0 beta169 | |
| Version 4.0.0 beta170 | |
| Version 4.0.0 beta171 | |
| Version 4.0.0 beta172 | |
| Version 4.0.0 beta173 | |
| Version 4.0.0 beta174 | |
| Version 4.0.0 beta175 | |
| Version 4.0.0 beta176 | |
| Version 4.0.0 beta177 | |
| Version 4.0.0 beta178 | |
| Version 4.0.0 beta179 | |
| Version 4.0.0 beta180 | |
| Version 4.0.0 beta181 | |
| Version 4.0.0 beta182 | |
| Version 4.0.0 beta183 | |
| Version 4.0.0 beta184 | |
| Version 4.0.0 beta185 | |
| Version 4.0.0 beta186 | |
| Version 4.0.0 beta187 | |
| Version 4.0.0 beta188 | |
| Version 4.0.0 beta189 | |
| Version 4.0.0 beta18 | |
| Version 4.0.0 beta190 | |
| Version 4.0.0 beta191 | |
| Version 4.0.0 beta192 | |
| Version 4.0.0 beta193 | |
| Version 4.0.0 beta194 | |
| Version 4.0.0 beta195 | |
| Version 4.0.0 beta196 | |
| Version 4.0.0 beta197 | |
| Version 4.0.0 beta198 | |
| Version 4.0.0 beta199 | |
| Version 4.0.0 beta19 | |
| Version 4.0.0 beta200 | |
| Version 4.0.0 beta201 | |
| Version 4.0.0 beta202 | |
| Version 4.0.0 beta203 | |
| Version 4.0.0 beta204 | |
| Version 4.0.0 beta205 | |
| Version 4.0.0 beta206 | |
| Version 4.0.0 beta207 | |
| Version 4.0.0 beta208 | |
| Version 4.0.0 beta209 | |
| Version 4.0.0 beta20 | |
| Version 4.0.0 beta211 | |
| Version 4.0.0 beta212 | |
| Version 4.0.0 beta213 | |
| Version 4.0.0 beta214 | |
| Version 4.0.0 beta215 | |
| Version 4.0.0 beta216 | |
| Version 4.0.0 beta217 | |
| Version 4.0.0 beta218 | |
| Version 4.0.0 beta219 | |
| Version 4.0.0 beta21 | |
| Version 4.0.0 beta220 | |
| Version 4.0.0 beta221 | |
| Version 4.0.0 beta222 | |
| Version 4.0.0 beta223 | |
| Version 4.0.0 beta224 | |
| Version 4.0.0 beta225 | |
| Version 4.0.0 beta226 | |
| Version 4.0.0 beta227 | |
| Version 4.0.0 beta228 | |
| Version 4.0.0 beta229 | |
| Version 4.0.0 beta22 | |
| Version 4.0.0 beta230 | |
| Version 4.0.0 beta231 | |
| Version 4.0.0 beta232 | |
| Version 4.0.0 beta233 | |
| Version 4.0.0 beta234 | |
| Version 4.0.0 beta235 | |
| Version 4.0.0 beta236 | |
| Version 4.0.0 beta237 | |
| Version 4.0.0 beta238 | |
| Version 4.0.0 beta239 | |
| Version 4.0.0 beta23 | |
| Version 4.0.0 beta240 | |
| Version 4.0.0 beta241 | |
| Version 4.0.0 beta242 | |
| Version 4.0.0 beta243 | |
| Version 4.0.0 beta244 | |
| Version 4.0.0 beta245 | |
| Version 4.0.0 beta246 | |
| Version 4.0.0 beta247 | |
| Version 4.0.0 beta248 | |
| Version 4.0.0 beta249 | |
| Version 4.0.0 beta24 | |
| Version 4.0.0 beta250 | |
| Version 4.0.0 beta251 | |
| Version 4.0.0 beta252 | |
| Version 4.0.0 beta253 | |
| Version 4.0.0 beta254 | |
| Version 4.0.0 beta255 | |
| Version 4.0.0 beta256 | |
| Version 4.0.0 beta257 | |
| Version 4.0.0 beta258 | |
| Version 4.0.0 beta259 | |
| Version 4.0.0 beta25 | |
| Version 4.0.0 beta260 | |
| Version 4.0.0 beta261 | |
| Version 4.0.0 beta262 | |
| Version 4.0.0 beta263 | |
| Version 4.0.0 beta264 | |
| Version 4.0.0 beta265 | |
| Version 4.0.0 beta266 | |
| Version 4.0.0 beta267 | |
| Version 4.0.0 beta268 | |
| Version 4.0.0 beta269 | |
| Version 4.0.0 beta26 | |
| Version 4.0.0 beta270 | |
| Version 4.0.0 beta271 | |
| Version 4.0.0 beta272 | |
| Version 4.0.0 beta273 | |
| Version 4.0.0 beta274 | |
| Version 4.0.0 beta275 | |
| Version 4.0.0 beta276 | |
| Version 4.0.0 beta277 | |
| Version 4.0.0 beta278 | |
| Version 4.0.0 beta279 | |
| Version 4.0.0 beta27 | |
| Version 4.0.0 beta280 | |
| Version 4.0.0 beta281 | |
| Version 4.0.0 beta282 | |
| Version 4.0.0 beta283 | |
| Version 4.0.0 beta284 | |
| Version 4.0.0 beta285 | |
| Version 4.0.0 beta286 | |
| Version 4.0.0 beta287 | |
| Version 4.0.0 beta288 | |
| Version 4.0.0 beta289 | |
| Version 4.0.0 beta28 | |
| Version 4.0.0 beta290 | |
| Version 4.0.0 beta291 | |
| Version 4.0.0 beta292 | |
| Version 4.0.0 beta293 | |
| Version 4.0.0 beta294 | |
| Version 4.0.0 beta295 | |
| Version 4.0.0 beta296 | |
| Version 4.0.0 beta297 | |
| Version 4.0.0 beta298 | |
| Version 4.0.0 beta299 | |
| Version 4.0.0 beta29 | |
| Version 4.0.0 beta300 | |
| Version 4.0.0 beta301 | |
| Version 4.0.0 beta302 | |
| Version 4.0.0 beta303 | |
| Version 4.0.0 beta304 | |
| Version 4.0.0 beta305 | |
| Version 4.0.0 beta306 | |
| Version 4.0.0 beta307 | |
| Version 4.0.0 beta308 | |
| Version 4.0.0 beta309 | |
| Version 4.0.0 beta30 | |
| Version 4.0.0 beta310 | |
| Version 4.0.0 beta311 | |
| Version 4.0.0 beta312 | |
| Version 4.0.0 beta313 | |
| Version 4.0.0 beta314 | |
| Version 4.0.0 beta315 | |
| Version 4.0.0 beta316 | |
| Version 4.0.0 beta317 | |
| Version 4.0.0 beta318 | |
| Version 4.0.0 beta319 | |
| Version 4.0.0 beta31 | |
| Version 4.0.0 beta320 | |
| Version 4.0.0 beta321 | |
| Version 4.0.0 beta322 | |
| Version 4.0.0 beta323 | |
| Version 4.0.0 beta324 | |
| Version 4.0.0 beta325 | |
| Version 4.0.0 beta326 | |
| Version 4.0.0 beta327 | |
| Version 4.0.0 beta328 | |
| Version 4.0.0 beta329 | |
| Version 4.0.0 beta32 | |
| Version 4.0.0 beta330 | |
| Version 4.0.0 beta331 | |
| Version 4.0.0 beta332 | |
| Version 4.0.0 beta333 | |
| Version 4.0.0 beta334 | |
| Version 4.0.0 beta335 | |
| Version 4.0.0 beta336 | |
| Version 4.0.0 beta337 | |
| Version 4.0.0 beta338 | |
| Version 4.0.0 beta339 | |
| Version 4.0.0 beta33 | |
| Version 4.0.0 beta340 | |
| Version 4.0.0 beta341 | |
| Version 4.0.0 beta342 | |
| Version 4.0.0 beta343 | |
| Version 4.0.0 beta344 | |
| Version 4.0.0 beta345 | |
| Version 4.0.0 beta346 | |
| Version 4.0.0 beta347 | |
| Version 4.0.0 beta348 | |
| Version 4.0.0 beta349 | |
| Version 4.0.0 beta34 | |
| Version 4.0.0 beta350 | |
| Version 4.0.0 beta351 | |
| Version 4.0.0 beta352 | |
| Version 4.0.0 beta353 | |
| Version 4.0.0 beta354 | |
| Version 4.0.0 beta355 | |
| Version 4.0.0 beta356 | |
| Version 4.0.0 beta357 | |
| Version 4.0.0 beta358 | |
| Version 4.0.0 beta359 | |
| Version 4.0.0 beta35 | |
| Version 4.0.0 beta360 | |
| Version 4.0.0 beta361 | |
| Version 4.0.0 beta362 | |
| Version 4.0.0 beta363 | |
| Version 4.0.0 beta364 | |
| Version 4.0.0 beta365 | |
| Version 4.0.0 beta366 | |
| Version 4.0.0 beta367 | |
| Version 4.0.0 beta368 | |
| Version 4.0.0 beta369 | |
| Version 4.0.0 beta36 | |
| Version 4.0.0 beta370 | |
| Version 4.0.0 beta371 | |
| Version 4.0.0 beta372 | |
| Version 4.0.0 beta373 | |
| Version 4.0.0 beta374 | |
| Version 4.0.0 beta375 | |
| Version 4.0.0 beta376 | |
| Version 4.0.0 beta377 | |
| Version 4.0.0 beta378 | |
| Version 4.0.0 beta379 | |
| Version 4.0.0 beta37 | |
| Version 4.0.0 beta380 | |
| Version 4.0.0 beta381 | |
| Version 4.0.0 beta382 | |
| Version 4.0.0 beta383 | |
| Version 4.0.0 beta384 | |
| Version 4.0.0 beta385 | |
| Version 4.0.0 beta386 | |
| Version 4.0.0 beta387 | |
| Version 4.0.0 beta388 | |
| Version 4.0.0 beta389 | |
| Version 4.0.0 beta38 | |
| Version 4.0.0 beta390 | |
| Version 4.0.0 beta391 | |
| Version 4.0.0 beta392 | |
| Version 4.0.0 beta393 | |
| Version 4.0.0 beta394 | |
| Version 4.0.0 beta395 | |
| Version 4.0.0 beta396 | |
| Version 4.0.0 beta397 | |
| Version 4.0.0 beta398 | |
| Version 4.0.0 beta399 | |
| Version 4.0.0 beta39 | |
| Version 4.0.0 beta400 | |
| Version 4.0.0 beta401 | |
| Version 4.0.0 beta402 | |
| Version 4.0.0 beta404 | |
| Version 4.0.0 beta405 | |
| Version 4.0.0 beta406 | |
| Version 4.0.0 beta407 | |
| Version 4.0.0 beta408 | |
| Version 4.0.0 beta409 | |
| Version 4.0.0 beta40 | |
| Version 4.0.0 beta410 | |
| Version 4.0.0 beta411 | |
| Version 4.0.0 beta412 | |
| Version 4.0.0 beta413 | |
| Version 4.0.0 beta414 | |
| Version 4.0.0 beta415 | |
| Version 4.0.0 beta416 | |
| Version 4.0.0 beta417 | |
| Version 4.0.0 beta418 | |
| Version 4.0.0 beta419 | |
| Version 4.0.0 beta41 | |
| Version 4.0.0 beta420.1 | |
| Version 4.0.0 beta420.2 | |
| Version 4.0.0 beta420.3 | |
| Version 4.0.0 beta420.4 | |
| Version 4.0.0 beta420.5 | |
| Version 4.0.0 beta420.6 | |
| Version 4.0.0 beta420 | |
| Version 4.0.0 beta42 | |
| Version 4.0.0 beta43 | |
| Version 4.0.0 beta44 | |
| Version 4.0.0 beta45 | |
| Version 4.0.0 beta46 | |
| Version 4.0.0 beta47 | |
| Version 4.0.0 beta48 | |
| Version 4.0.0 beta49 | |
| Version 4.0.0 beta50 | |
| Version 4.0.0 beta51 | |
| Version 4.0.0 beta52 | |
| Version 4.0.0 beta53 | |
| Version 4.0.0 beta54 | |
| Version 4.0.0 beta55 | |
| Version 4.0.0 beta56 | |
| Version 4.0.0 beta57 | |
| Version 4.0.0 beta58 | |
| Version 4.0.0 beta59 | |
| Version 4.0.0 beta60 | |
| Version 4.0.0 beta61 | |
| Version 4.0.0 beta62 | |
| Version 4.0.0 beta63 | |
| Version 4.0.0 beta64 | |
| Version 4.0.0 beta65 | |
| Version 4.0.0 beta66 | |
| Version 4.0.0 beta67 | |
| Version 4.0.0 beta68 | |
| Version 4.0.0 beta69 | |
| Version 4.0.0 beta70 | |
| Version 4.0.0 beta71 | |
| Version 4.0.0 beta72 | |
| Version 4.0.0 beta73 | |
| Version 4.0.0 beta74 | |
| Version 4.0.0 beta75 | |
| Version 4.0.0 beta76 | |
| Version 4.0.0 beta77 | |
| Version 4.0.0 beta78 | |
| Version 4.0.0 beta79 | |
| Version 4.0.0 beta80 | |
| Version 4.0.0 beta81 | |
| Version 4.0.0 beta82 | |
| Version 4.0.0 beta83 | |
| Version 4.0.0 beta84 | |
| Version 4.0.0 beta85 | |
| Version 4.0.0 beta86 | |
| Version 4.0.0 beta87 | |
| Version 4.0.0 beta88 | |
| Version 4.0.0 beta89 | |
| Version 4.0.0 beta90 | |
| Version 4.0.0 beta91 | |
| Version 4.0.0 beta92 | |
| Version 4.0.0 beta93 | |
| Version 4.0.0 beta94 | |
| Version 4.0.0 beta95 | |
| Version 4.0.0 beta96 | |
| Version 4.0.0 beta97 | |
| Version 4.0.0 beta98 | |
| Version 4.0.0 beta99 |
Related CWEs
CWE-116
Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
References (1)
Source: security-advisories@github.com
ExploitVendor Advisory
Timeline
No history available yet.