Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 12 Jan 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coollabs
Coollabs coolify |
|
| CPEs | cpe:2.3:a:coollabs:coolify:4.0.0:beta428:*:*:*:*:*:* | |
| Vendors & Products |
Coollabs
Coollabs coolify |
|
| Metrics |
cvssV3_1
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coollabsio
Coollabsio coolify |
|
| Vendors & Products |
Coollabsio
Coollabsio coolify |
Mon, 05 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members` API endpoints allows authenticated team members to access a highly sensitive `email_change_code` from other users on the same team. This code is intended for a single-use email change verification and should be kept secret. Its exposure could enable a malicious actor to perform an unauthorized email address change on behalf of the victim. As of time of publication, no known patched versions exist. | |
| Title | Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint | |
| Weaknesses | CWE-201 CWE-212 CWE-214 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-05T17:59:28.044Z
Reserved: 2025-09-23T14:33:49.506Z
Link: CVE-2025-59955
Updated: 2026-01-05T17:58:15.441Z
Status : Analyzed
Published: 2026-01-05T18:15:43.927
Modified: 2026-01-12T14:48:13.057
Link: CVE-2025-59955
No data.
OpenCVE Enrichment
Updated: 2026-01-06T14:16:22Z