cbcvebase.
CVE-2026-55427
published 2026-07-08

CVE-2026-55427: Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh`…

PriorityP349high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
0.47%
39.6th percentile
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration. Practical exploitation requires control of the server-supplied values through a malicious or compromised deployment, a man-in-the-middle position or admin access to the `HostnameSuffix` and `SSHConfigOptions` settings. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `HostnameSuffix` and `SSHConfigOptions` against a strict character set that rejects newlines and other control characters. As a workaround, inspect `coder config-ssh --dry-run` output before applying changes.

Affected

11 ranges
VendorProductVersion rangeFixed in
codercoder< 2.29.172.29.17
codercoder——
codercoder——
codercoder——
codercoder>= 2.30.0 < 2.32.72.32.7
codercoder>= 2.33.0 < 2.33.82.33.8
codercoder>= 2.34.0 < 2.34.22.34.2
github.comcoder_coder_v2>= 0 < 2.29.172.29.17
github.comcoder_coder_v2>= 2.30.0 < 2.32.72.32.7
github.comcoder_coder_v2>= 2.33.0 < 2.33.82.33.8
github.comcoder_coder_v2>= 2.34.0 < 2.34.22.34.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.