Eyodav/CVE-2025-34157

Eyodav/CVE-2025-34157

Releases0
A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to delete a project created by a low-privileged user. This can lead to takeover of the Coolify instance (cookies, API tokens, WebSocket/terminal actions)

Collections containing this project

Showing collections based on your access.

This project is not in any collections you can view.