{"id":"CVE-2025-59158","title":"Coolify is an open-source and self-hostable tool for managing servers, applications, and databases","summary":"Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project cre…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-116","CWE-79"],"vendor":"coollabs","product":"coolify","affected":["coolify < 4.0.0","coolify = 4.0.0"],"patched":["coolify 4.0.0"],"published":"2026-01-05","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:10:00.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-59158","references":[{"url":"https://github.com/coollabsio/coolify/security/advisories/GHSA-h52r-jxv9-9vhf","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00487,"epssPercentile":0.39619,"ingestedAt":"2026-09-30T22:27:27.691Z","slug":"CVE-2025-59158","body":"## Overview\n\nCoolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator later attempts to delete the project or its associated resource, the payload automatically executes in the admin’s browser context. Version 4.0.0-beta.420.7 contains a patch for the issue.\n\n## Affected\n\n- `coolify < 4.0.0`\n- `coolify = 4.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `coolify 4.0.0`","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}