Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6p37-qg9q-mprw

Опубликовано: 27 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 9

Описание

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the admin’s browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the admin’s browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.

EPSS

Процентиль: 16%
0.00051
Низкий

9.4 Critical

CVSS4

9 Critical

CVSS3

Дефекты

CWE-20
CWE-79

Связанные уязвимости

CVSS3: 9
nvd
5 месяцев назад

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the admin’s browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.

EPSS

Процентиль: 16%
0.00051
Низкий

9.4 Critical

CVSS4

9 Critical

CVSS3

Дефекты

CWE-20
CWE-79