External risk intelligence

Coolify Stored Cross-Site Scripting Vulnerability in Project Creation

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-59158

Coolify is a self-hostable server and application management platform. These tools are commonly deployed as internet-accessible web-based management consoles or edge services used to orchestrate infrastructure, making their web interfaces reachable in typical deployment scenarios.

Cross-site Scripting

Coollabs Coolify

before 4.0.04.0.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in Coolify, an open-source tool for managing servers and applications, that could allow a low-privilege user to execute malicious code within an administrator's browser. This occurs when an administrator interacts with a project created with a specially crafted name, potentially impacting the integrity of administrative operations. The primary concern is to verify if this specific technology is in use and assess any exposure.

  • Malicious code execution via project names.
  • Impacts administrative control of server management.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low-privilege access can create a new project using a name that contains malicious JavaScript code. This code will execute when an administrator attempts to delete the project or its related resources, potentially leading to broader system compromise.

  • Authenticated, low-privilege user required.
  • Triggered by project deletion action.
  • Risk of administrator browser compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact the Coolify application by allowing an authenticated user, even with a low-privilege role, to inject malicious JavaScript into a project name. This script could execute in the browser of an administrator when they interact with the project, potentially affecting their session or actions within the Coolify interface. No specific system data, user data, or PII is indicated as being at risk based on the provided context.

  • Administrator sessions and actions within Coolify.
  • Malicious script execution via project deletion.
  • Compromised administrator actions within the tool.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Coolify, a self-hosted server and application management tool. Ownership likely falls to the platform or infrastructure teams responsible for deploying and managing Coolify instances, in coordination with security teams for exposure assessment. The first practical step is to inventory all Coolify deployments, identify which are externally accessible, and then determine the responsible team for remediation.

  • Platform or infrastructure teams own the issue.
  • Verify external accessibility and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Coolify?

Coolify is an open-source, self-hostable platform designed to simplify the management of servers, applications, and databases. It provides a web-based dashboard that helps developers and infrastructure teams automate deployment and orchestration workflows.

What does CWE-79 mean in the context of CVE-2025-59158?

CWE-79 is a classification for Cross-Site Scripting (XSS). In this vulnerability, it means the application fails to properly sanitize user-provided text, allowing malicious JavaScript to be saved and later executed by an administrator’s browser when they manage a project.

How is this vulnerability triggered?

An attacker with low-privilege access must create a project with a malicious name containing JavaScript. The attack only triggers when an administrator later attempts to delete that specific project or its resources, causing the script to run in their session.

Is my Coolify instance at risk?

Halo Surface Signal notes that because Coolify is often deployed as an internet-accessible management console, its interface is frequently reachable. If your instance is exposed to the internet, low-privilege users could potentially reach the dashboard.

What should I do if I am running Coolify?

Identify all active Coolify instances and confirm their version numbers. If you are running a version prior to 4.0.0-beta.420.7, prioritize updating to that version or newer to apply the official patch for this vulnerability.

References