CVE-2025-34157

CRITICAL

Coolify < 4.0.0-beta.420.6 - Authenticated Stored Cross-Site Scripting in Project Name

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-34157. PoCs published by Eyodav.

AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2025-34157, a stored XSS vulnerability in Coolify ≤ v4.0.0-beta.420.6. The exploit allows a low-privileged user to inject malicious JavaScript into a project name, which executes when an administrator attempts to delete the project.

Description

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the admin’s browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.

Exploits (1)

nomisec WORKING POC
by Eyodav · poc
https://github.com/Eyodav/CVE-2025-34157

This repository contains a proof-of-concept for CVE-2025-34157, a stored XSS vulnerability in Coolify ≤ v4.0.0-beta.420.6. The exploit allows a low-privileged user to inject malicious JavaScript into a project name, which executes when an administrator attempts to delete the project.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Coolify ≤ v4.0.0-beta.420.6
Auth required
Prerequisites: Authenticated low-privileged user account · Administrator interaction to delete the project
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Product product
https://coolify.io/
Third Party Advisory technical-description exploit
https://github.com/Eyodav/CVE-2025-34157

Scores

CVSS v3 9.0
EPSS 0.0045
EPSS Percentile 35.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-79
Status published
Products (1)
coollabs/coolify 4.0.0 beta100 (50 CPE variants)
Published Aug 27, 2025
Tracked Since Feb 18, 2026