PatchSiren cyber security CVE debrief
CVE-2025-59955 Coollabs CVE debrief
CVE-2025-59955 is an information disclosure vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. Versions prior to and including v4.0.0-beta.420.8 are affected. The vulnerability allows authenticated team members to access a highly sensitive `email_change_code` from other users on the same team via the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members` API endpoints. This code is intended for single-use email change verification and should be kept secret. Exposure of this code could enable a malicious actor to perform an unauthorized email address change on behalf of the victim. As of the time of publication, no known patched versions exist.
- Vendor
- Coollabs
- Product
- Coolify
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-05
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-05
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for managing servers, applications, and databases using Coolify should assess exposure and prioritize verification and mitigation efforts. This includes IT security teams, system administrators, and developers using Coolify in their environments.
Why it matters
CVE-2025-59955 is a medium-severity information disclosure vulnerability in Coolify that allows authenticated team members to access sensitive email change codes of other users on the same team. Defenders should prioritize verifying exposure, assessing the need for compensating controls, and monitoring for potential exploitation attempts. The vulnerability's impact is limited by the requirement for authentication as a team member, but its exploitation could lead to unauthorized email address changes.
- Potential unauthorized email address changes on behalf of victims.
- Exposure of sensitive email change codes.
- Possible lateral movement within teams.
- Need for verification of exposure and compensating controls.
Technical summary
The vulnerability is located in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members` API endpoints of Coolify. Authenticated team members can access the highly sensitive `email_change_code` of other users on the same team. This code is intended for single-use email change verification and should be kept secret. Exposure of this code could enable a malicious actor to perform an unauthorized email address change on behalf of the victim.
Defensive priority
Defenders should prioritize verifying exposure and assessing the need for compensating controls, given the limited information available on patched versions and remediation.
Recommended defensive actions
- Verify exposure by checking if the affected API endpoints are accessible and if team members can access email change codes of other users.
- Assess the need for compensating controls, such as additional authentication or access controls, to mitigate the risk of unauthorized email address changes.
- Monitor for any updates from the vendor on patched versions and apply them as soon as available.
- Consider implementing additional logging and monitoring to detect potential exploitation attempts.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and affected versions. However, information on patched versions and specific remediation steps is limited. Coolify versions prior to and including v4.0.0-beta.420.8 are affected. Defenders should verify exposure by checking if the affected API endpoints are accessible and if team members can access email change codes of other users. They should also assess the need for compensating controls, such as additional authentication or access controls, to mitigate
Sources and references
Verified primary and authoritative sources
-
CVE-2025-59955 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-59955
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-59955 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-59955
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-927g-56xp-6427
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.