Executive brief
Coolify, an open-source platform for deploying and managing web applications and databases, is vulnerable to a security flaw that allows low-privileged users to take over the entire system. By creating a project with a specially crafted name, an attacker can execute malicious code in an administrator's browser when the admin attempts to delete that project. This could lead to the theft of sensitive API tokens, session cookies, and unauthorized access to terminal sessions on managed servers.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Coolify's project creation workflow due to improper input validation of project names. An authenticated attacker with low privileges (e.g., a 'member' role) can inject a malicious JavaScript payload into a project name. When an administrator interacts with the project—specifically during the deletion flow or when viewing associated resources—the payload executes within the administrator's browser context. This enables the attacker to perform actions with administrative privileges, including stealing session cookies, API tokens, and hijacking WebSocket-based terminal sessions on managed servers. The issue is fixed in version v4.0.0-beta.420.7.
Affected products
- coollabsio Coolify prior to v4.0.0-beta.420.7
Timeline
- 2025-08-26: patched: Fixed in version v4.0.0-beta.420.7
- 2025-08-27: advisory: CVE-2025-34157 published