CVE-2025-59955 Details
Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members` API endpoints allows authenticated team members to access a highly sensitive `email_change_code` from other users on the same team. This code is intended for a single-use email change verification and should be kept secret. Its exposure could enable a malicious actor to perform an unauthorized email address change on behalf of the victim. As of time of publication, no known patched versions exist.
A vulnerability allowing information disclosure has been identified in Coolify, an open-source tool for managing servers, applications, and databases. This issue affects Coolify versions through v4.0.0-beta.420.8. The vulnerability resides in the '/api/v1/teams/{team_id}/members' and '/api/v1/teams/current/members' API endpoints. It allows authenticated team members to access a sensitive 'email_change_code' from other users on the same team. This code, meant for single-use email change verification, should remain confidential. Its unauthorized exposure could enable a malicious actor to change a victim's email address without permission.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/coollabsio/coolify/security/advisories/GHSA-927g-56xp-6427 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | [email protected] |
| CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer | [email protected] |
| CWE-214 | Invocation of Process Using Visible Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| coollabs coolify | 4.0.0 beta428 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | Initial Analysis | [email protected] |
| Jan 5, 2026 | New CVE Received | [email protected] |