CVE-2025-59955: Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the /api/v1/teams/{teamid}/members and /api/v1/teams/current/members API endpoints allows authenticated team members to access a highly sensitive emailchangecode from other users on the same team. This code is intended for a single-use email change verification and should be kept secret. Its exposure could enable a malicious actor to perform an unauthorized email address change on behalf of the victim. As of time of publication, no known patched versions exist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59955?
CVE-2025-59955 is classified as a high-severity information disclosure vulnerability.
How do I fix CVE-2025-59955?
To fix CVE-2025-59955, upgrade Coolify to version 4.0.0-beta.420.9 or later.
What specific versions are affected by CVE-2025-59955?
CVE-2025-59955 affects Coolify versions up to and including 4.0.0-beta.420.8.
What types of data are exposed in CVE-2025-59955?
CVE-2025-59955 allows unauthorized access to team member information via specific API endpoints.
Is there a workaround for CVE-2025-59955 until I can upgrade?
There are no specific workarounds recommended for CVE-2025-59955, so upgrading is the best solution.