Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Google integrates Gemini CLI into Zed code editor

      August 28, 2025

      10 Benefits of Integrating React.js Vibe Coding into Your Agile DevOps Pipeline

      August 28, 2025

      Designing For TV: The Evergreen Pattern That Shapes TV Experiences

      August 27, 2025

      Amplitude launches new self-service capabilities for marketing initiatives

      August 27, 2025

      How GitHub Models can help open source maintainers focus on what matters

      August 28, 2025

      How we accelerated Secret Protection engineering with Copilot

      August 28, 2025

      Interactive Video Projection Mapping with Three.js

      August 28, 2025

      Representative Line: Springs are Optional

      August 28, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Heartbeat Collection Method in Laravel 12.26; Wayfinder Now in React and Vue Starter Kits

      August 28, 2025
      Recent

      Heartbeat Collection Method in Laravel 12.26; Wayfinder Now in React and Vue Starter Kits

      August 28, 2025

      spatie/laravel-rdap

      August 28, 2025

      mvanduijker/laravel-mercure-broadcaster

      August 28, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Firefox’s On-Device AI Features Now Up to 10x Faster

      August 28, 2025
      Recent

      Firefox’s On-Device AI Features Now Up to 10x Faster

      August 28, 2025

      Ubuntu 25.10 Snapshot 4 is Available to Download

      August 28, 2025

      SuperTuxKart Evolution Promises ‘Fresh Experience’

      August 28, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-34159 – Coolify Docker Compose Remote Code Execution Vulnerability

    CVE-2025-34159 – Coolify Docker Compose Remote Code Execution Vulnerability

    August 27, 2025

    CVE ID : CVE-2025-34159

    Published : Aug. 27, 2025, 5:15 p.m. | 8 hours, 34 minutes ago

    Description : Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project creation. By crafting a malicious service definition that mounts the host root filesystem, an attacker can gain full root access to the underlying server.

    Severity: 9.4 | CRITICAL

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-34161 – Coolify Remote Code Execution Vulnerability
    Next Article CVE-2025-34157 – Coolify Stored XSS Vulnerability

    Related Posts

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-53216 – ThemeUniver Glamer PHP RFI

    August 28, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-53227 – Unfoldwp Magazine Saga PHP Remote File Inclusion Vulnerability

    August 28, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-9036 – Citrix Workspace Token Replay Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-7816 – PHPGurukul Apartment Visitors Management System Cross-Site Scripting Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    How to Upload Large Objects to S3 with AWS CLI Multipart Upload

    Development

    CVE-2025-3895 – MegaBIP Password Reset Token Brute Force Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    CVE-2025-4595 – FastSpring for WordPress Stored Cross-Site Scripting Vulnerability

    May 31, 2025

    CVE ID : CVE-2025-4595

    Published : May 31, 2025, 7:15 a.m. | 2 hours, 27 minutes ago

    Description : The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘fastspring/block-fastspringblocks-complete-product-catalog’ block in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping on the ‘color’ attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Severity: 6.4 | MEDIUM

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    CVE-2025-27754 – Joomla RSBlog! Stored Cross-Site Scripting (XSS) Vulnerability

    June 5, 2025

    CVE-2025-47768 – Cisco ASA SSL/TLS Certificate Pinning Bypass

    May 10, 2025

    CVE-2025-6689 – “FL3R Accessibility Suite Plugin Stored XSS Vulnerability”

    June 27, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.