CVE-2026-5301
HIGH
NVD
CVSS Score
7.6
Severity
HIGH
Published
Apr 08, 2026
Vendor
unknown
Description
Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries
References
- https://gitlab.com/coolercontrol/coolercontrol/-/blob/2.0.0/coolercontrol-ui/src/views/AppInfoView.vue?ref_type=tags#L224
- https://gitlab.com/coolercontrol/coolercontrol/-/blob/3.1.1/coolercontrol-ui/src/views/AppInfoView.vue?ref_type=tags#L350
- https://gitlab.com/coolercontrol/coolercontrol/-/releases/4.0.0