Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the admin’s browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.
History

Fri, 19 Sep 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Coollabs
Coollabs coolify
CPEs cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta100:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta101:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta102:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta103:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta104:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta105:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta106:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta107:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta108:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta109:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta110:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta111:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta112:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta113:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta114:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta115:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta116:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta117:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta118:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta119:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta120:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta121:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta122:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta123:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta124:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta125:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta126:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta127:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta128:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta129:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta130:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta131:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta132:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta133:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta134:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta135:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta136:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta137:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta138:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta139:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta140:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta141:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta142:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta143:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta144:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta145:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta146:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta147:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta148:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta149:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta150:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta151:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta152:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta153:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta154:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta155:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta156:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta157:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta158:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta159:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta160:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta161:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta162:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta163:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta164:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta165:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta166:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta167:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta168:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta169:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta170:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta171:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta172:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta173:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta174:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta175:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta176:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta177:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta178:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta179:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta180:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta181:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta182:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta183:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta184:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta185:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta186:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta187:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta188:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta189:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta18:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta190:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta191:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta192:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta193:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta194:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta195:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta196:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta197:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta198:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta199:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta19:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta200:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta201:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta202:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta203:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta204:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta205:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta206:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta207:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta208:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta209:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta20:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta211:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta212:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta213:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta214:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta215:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta216:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta217:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta218:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta219:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta21:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta220:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta221:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta222:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta223:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta224:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta225:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta226:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta227:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta228:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta229:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta22:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta230:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta231:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta232:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta233:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta234:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta235:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta236:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta237:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta238:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta239:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta23:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta240:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta241:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta242:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta243:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta244:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta245:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta246:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta247:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta248:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta249:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta24:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta250:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta251:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta252:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta253:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta254:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta255:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta256:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta257:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta258:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta259:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta25:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta260:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta261:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta262:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta263:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta264:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta265:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta266:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta267:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta268:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta269:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta26:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta270:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta271:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta272:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta273:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta274:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta275:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta276:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta277:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta278:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta279:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta27:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta280:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta281:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta282:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta283:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta284:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta285:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta286:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta287:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta288:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta289:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta28:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta290:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta291:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta292:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta293:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta294:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta295:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta296:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta297:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta298:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta299:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta29:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta300:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta301:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta302:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta303:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta304:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta305:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta306:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta307:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta308:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta309:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta30:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta310:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta311:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta312:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta313:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta314:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta315:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta316:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta317:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta318:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta319:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta31:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta320:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta321:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta322:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta323:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta324:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta325:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta326:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta327:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta328:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta329:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta32:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta330:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta331:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta332:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta333:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta334:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta335:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta336:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta337:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta338:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta339:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta33:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta340:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta341:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta342:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta343:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta344:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta345:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta346:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta347:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta348:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta349:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta34:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta350:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta351:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta352:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta353:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta354:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta355:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta356:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta357:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta358:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta359:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta35:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta360:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta361:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta362:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta363:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta364:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta365:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta366:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta367:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta368:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta369:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta36:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta370:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta371:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta372:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta373:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta374:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta375:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta376:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta377:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta378:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta379:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta37:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta380:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta381:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta382:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta383:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta384:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta385:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta386:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta387:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta388:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta389:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta38:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta390:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta391:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta392:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta393:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta394:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta395:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta396:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta397:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta398:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta399:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta39:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta400:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta401:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta402:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta404:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta405:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta406:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta407:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta408:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta409:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta40:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta410:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta411:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta412:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta413:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta414:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta415:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta416:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta417:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta418:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta419:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta41:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta420.1:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta420.2:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta420.3:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta420.4:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta420.5:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta420.6:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta420:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta42:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta43:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta44:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta45:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta46:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta47:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta48:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta49:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta50:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta51:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta52:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta53:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta54:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta55:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta56:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta57:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta58:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta59:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta60:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta61:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta62:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta63:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta64:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta65:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta66:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta67:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta68:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta69:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta70:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta71:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta72:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta73:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta74:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta75:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta76:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta77:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta78:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta79:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta80:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta81:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta82:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta83:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta84:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta85:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta86:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta87:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta88:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta89:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta90:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta91:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta92:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta93:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta94:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta95:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta96:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta97:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta98:*:*:*:*:*:*
cpe:2.3:a:coollabs:coolify:4.0.0:beta99:*:*:*:*:*:*
Vendors & Products Coollabs
Coollabs coolify
Metrics cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Wed, 27 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 Aug 2025 17:00:00 +0000

Type Values Removed Values Added
Description Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the admin’s browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.
Title Coolify Stored Cross-Site Scripting (XSS) in Project Name Field
Weaknesses CWE-20
CWE-79
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-08-27T16:48:03.027Z

Updated: 2025-08-27T17:47:18.634Z

Reserved: 2025-04-15T19:15:22.565Z

Link: CVE-2025-34157

cve-icon Vulnrichment

Updated: 2025-08-27T17:47:03.167Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-27T17:15:37.930

Modified: 2025-09-19T16:48:52.820

Link: CVE-2025-34157

cve-icon Redhat

No data.