CVE-2026-5301

Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries
Configurations

Configuration 1 (hide)

cpe:2.3:a:coolercontrol:coolercontrold:*:*:*:*:*:*:*:*

History

16 Apr 2026, 00:47

Type Values Removed Values Added
First Time Coolercontrol coolercontrold
Coolercontrol
References () https://gitlab.com/coolercontrol/coolercontrol/-/blob/2.0.0/coolercontrol-ui/src/views/AppInfoView.vue?ref_type=tags#L224 - () https://gitlab.com/coolercontrol/coolercontrol/-/blob/2.0.0/coolercontrol-ui/src/views/AppInfoView.vue?ref_type=tags#L224 - Product
References () https://gitlab.com/coolercontrol/coolercontrol/-/blob/3.1.1/coolercontrol-ui/src/views/AppInfoView.vue?ref_type=tags#L350 - () https://gitlab.com/coolercontrol/coolercontrol/-/blob/3.1.1/coolercontrol-ui/src/views/AppInfoView.vue?ref_type=tags#L350 - Product
References () https://gitlab.com/coolercontrol/coolercontrol/-/releases/4.0.0 - () https://gitlab.com/coolercontrol/coolercontrol/-/releases/4.0.0 - Release Notes
CPE cpe:2.3:a:coolercontrol:coolercontrold:*:*:*:*:*:*:*:*

08 Apr 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 13:16

Updated : 2026-04-16 00:47


NVD link : CVE-2026-5301

Mitre link : CVE-2026-5301

CVE.ORG link : CVE-2026-5301


JSON object : View

Products Affected

coolercontrol

  • coolercontrold
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')