Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator later attempts to delete the project or its associated resource, the payload automatically executes in the admin’s browser context. Version 4.0.0-beta.420.7 contains a patch for the issue.
Conclusion & alert: CVE-2025-59158 is rated High Exploit Risk (66/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.47%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.47% | +0.43% |
| 2 | 2026-06-03 | 0.05% | 0.05% | -0.00% |
| 3 | 2026-02-06 | — | 0.05% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.4 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 8.0 | 3.1 | HIGH |
|
2.1 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| coollabs | coolify | < 4.0.0 | cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta100:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta101:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta102:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta103:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta104:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta105:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta106:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta107:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta108:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta109:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta110:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta111:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta112:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta113:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta114:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta115:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta116:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta117:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta118:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta119:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta120:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta121:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta122:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta123:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta124:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta125:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta126:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta127:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta128:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta129:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta130:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta131:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta132:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta133:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta134:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta135:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta136:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta137:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta138:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta139:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta140:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta141:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta142:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta143:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta144:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta145:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta146:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta147:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta148:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta149:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta150:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta151:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta152:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta153:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta154:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta155:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta156:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta157:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta158:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta159:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta160:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta161:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta162:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta163:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta164:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta165:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta166:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta167:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta168:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta169:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta170:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta171:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta172:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta173:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta174:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta175:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta176:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta177:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta178:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/coollabsio/coolify/security/advisories/GHSA-h52r-jxv9-9vhf | Exploit Vendor Advisory |