PatchSiren

CoolerControl CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH CoolerControl CVE published 2026-04-08

CVE-2026-5301

CVE-2026-5301 is a high-severity vulnerability in CoolerControl's log viewer, allowing unauthenticated attackers to execute malicious JavaScript via poisoned log entries. The vulnerability exists in versions prior to 4.0.0 of the coolercontrol-ui package. This stored XSS (Cross-Site Scripting) issue enables attackers to inject malicious code into log entries, which can then be executed by other users who [truncated]

MEDIUM CoolerControl CVE published 2026-04-08

CVE-2026-5300

CVE-2026-5300 is a medium-severity vulnerability in CoolerControl/coolercontrold that allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests. The vulnerability has a CVSS score of 5.9 and is classified as CWE-306. It affects CoolerControl/coolercontrold versions prior to 4.0.0. Users should review official advisories and take steps to mitigate the vulnerability.