HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in coolercontrol-ui
Published Apr 8, 2026
7.6
HIGHCVSS 3.1
EPSS 0.37%
Description
Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries
Affected products
-
- Version 2.0.0StatusaffectedConstraints<4.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| CoolerControl | Coolercontrol-UI | unaffected |
|
- < 4.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 4.0.0
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-20459 Advisory
- https://gitlab.com/coolercontrol/coolercontrol/-/blob/2.0.0/coolercontrol-ui/src/views/AppInfoView.vue?ref_type=tags#L224 Product
- https://gitlab.com/coolercontrol/coolercontrol/-/blob/3.1.1/coolercontrol-ui/src/views/AppInfoView.vue?ref_type=tags#L350 Product
- https://gitlab.com/coolercontrol/coolercontrol/-/releases/4.0.0 Release Notes
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 8, 2026
Updated Apr 8, 2026
Reserved Apr 1, 2026
Link CVE-2026-5301
CISA Vulnrichment
Updated Apr 8, 2026
ENISA EUVD
EUVD-2026-20459 Assigner GitLab
Published Apr 8, 2026
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2026-20459