Executive brief
CoolerControl is a software suite used to monitor and control hardware cooling systems like fans and liquid coolers. A security flaw in the background service allows malicious websites to bypass browser security protections. If a user visits a compromised site while the software is running, an attacker could remotely view system data or change cooling settings, potentially leading to hardware overheating or unauthorized system access.
Technical details
A Cross-Origin Resource Sharing (CORS) misconfiguration exists in the coolercontrold API in versions prior to 4.0.0. The service implements a permissive cross-domain policy (CWE-942) that fails to properly restrict which origins can interact with the local API. An attacker can exploit this by enticing a user to visit a malicious website, which then uses the user's browser as a proxy to send unauthorized requests to the local coolercontrold service. This allows for unauthenticated data exfiltration and the execution of commands. The issue is resolved in version 4.0.0.
Affected products
- CoolerControl coolercontrold < 4.0.0
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched: Fixed in version 4.0.0