CVE-2025-34157 is a stored cross-site scripting vulnerability affecting Coolify versions prior to v4.0.0-beta.420.6. The flaw exists in the project creation workflow, where a low-privileged authenticated user can supply a malicious project name containing embedded JavaScript. That attacker-controlled input is later rendered in an administrator-facing context without sufficient output encoding or sanitization. When an administrator attempts to delete the project or an associated resource, the stored payload executes in the administrator’s browser session. Because the script runs in the admin’s authenticated context within the Coolify application, the vulnerability can be used to compromise sensitive application data and administrative functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-34157, a stored cross-site scripting (XSS) vulnerability in Coolify versions up to and including v4.0.0-beta.420.6. The exploit demonstrates how a low-privileged user can create a project with a malicious name containing HTML/JavaScript payloads. When an administrator attempts to delete this project, the payload executes in the admin's browser, enabling session hijacking, token theft, and potentially full compromise of the Coolify instance. The repository contains four files: - `POC/Payloads HTMLi`: A collection of various HTML injection payloads, including tags, encoded variants, and elements with external references (e.g., iframes, images, audio, and embeds). - `POC/Payloads XSS`: A set of XSS-specific payloads, including event handler exploits and JavaScript URIs, designed to trigger JavaScript execution in the browser. - `POC/ReadMe.md`: Detailed documentation of the vulnerability, exploitation steps, and impact, including the main PoC payload and attack scenario. - `README.md`: A summary of the vulnerability, affected versions, and references. No actual code is present; the repository consists of payload samples and markdown documentation. The main exploit capability is stored XSS via project name, targeting the Coolify admin interface. The attack vector is browser-based, requiring admin interaction. The endpoints referenced in the payloads (e.g., google.com, index.html, index.jpg) are for demonstration and do not represent real targets in Coolify. The repository is a PoC and does not include weaponized or automated exploitation scripts.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.