CVE-2025-59955
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members` API endpoints allows authenticated team members to access a highly sensitive `email_change_code` from other users on the same team. This code is intended for a single-use email change verification and should be kept secret. Its exposure could enable a malicious actor to perform an unauthorized email address change on behalf of the victim. As of time of publication, no known patched versions exist.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.30%
- CWE
- CWE-201, CWE-212, CWE-214
- Published
- 2026-01-05
- Last modified
- 2026-03-13
Affected products
- coollabsio coolify
Weakness type
Related vulnerabilities
- CVE-2026-65812 — Microsoft Teams for Android Information Disclosure Vulnerability
- CVE-2026-86505 — In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to...
- CVE-2026-86497 — In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed...
- CVE-2026-85307 — WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability
- CVE-2026-77123 — Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API
- CVE-2026-81162 — DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112
- CVE-2026-81280 — WordPress Print Barcode Labels for your WooCommerce products/orders plugin <= 4.0.0 - Sensitive Data Exposure vulnerability
- CVE-2026-55553 — urllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage