CVE-2026-5301

Publication date

2026-04-08 12:04:51

Family

GitLab

State

PUBLISHED

Description

Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries