Skip to content

Reflected XSS on Tag Search

Moderate
andrasbacsai published GHSA-f2gf-jvmh-vq73 Jan 24, 2025

Package

coolify (coollabsio)

Affected versions

< v4.0.0-beta.361

Patched versions

v4.0.0-beta.361

Description

The tags page allows users to search for tags. If the search does not return any results, the query gets reflected on the error modal, which leads to an XSS.

Severity

Moderate

CVE ID

CVE-2025-24025

Weaknesses

Credits