cbcvebase.

Github.Com Coder Coder V2 vulnerabilities

23 known vulnerabilities affecting github.com/coder_coder_v2.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM10

Vulnerabilities

Page 1 of 2
CVE-2026-46354P2CRITICAL≥ 2.33.0-rc.0, < 2.33.3≥ 2.32.0-rc.0, < 2.32.2+4 more2026-05-19
CVE-2026-46354 [CRITICAL] CWE-347 Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft ## Summary `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":""}` and the
ghsa
CVE-2026-44454P2HIGH≥ 0, < 2.29.7≥ 2.30.0, < 2.30.22026-07-02
CVE-2026-44454 [HIGH] CWE-78 Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent # Command injection via dotfiles URI parameter combined with workspace auto-creation ## Summary The `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted `dotfiles_
ghsa
CVE-2024-27918P3HIGH≥ 2.8.0, < 2.8.4≥ 2.7.0, < 2.7.3+1 more2024-03-04
CVE-2024-27918 [HIGH] CWE-20 Coder's OIDC authentication allows email with partially matching domain to register Coder's OIDC authentication allows email with partially matching domain to register ### Summary A vulnerability in Coder's OIDC authentication could allow an attacker to bypass the `CODER_OIDC_EMAIL_DOMAIN` verification and create an account with an email not in the allowlist. Deployments are only affected if the OIDC provider allows users to create accounts on the provider (such as
ghsaosv
CVE-2026-55428P3HIGH≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55428 [HIGH] CWE-285 Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator ### Summary The tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the
ghsa
CVE-2026-55429P3HIGH≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55429 [HIGH] CWE-639 Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID ### Summary `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.A
ghsa
CVE-2026-55427P3HIGH≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55427 [HIGH] CWE-74 Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` ### Summary `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary
ghsa
CVE-2026-55077P3HIGH≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55077 [HIGH] CWE-285 Coder: User-admin role can reset owner account password Coder: User-admin role can reset owner account password ### Summary The `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password. > **Note:** Exploitation requires the privileged `user-admin` role so practical risk
ghsa
CVE-2026-55076P3HIGH≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55076 [HIGH] CWE-287 Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking ### Summary Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified.
ghsa
CVE-2026-55075P3HIGH≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55075 [HIGH] CWE-287 Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass ### Summary Two flaws in Coder's OIDC login chained into account takeover: email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the `email_verified` claim was only enforced when present as a boolean `
ghsa
CVE-2026-55436P3HIGH≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+1 more2026-07-06
CVE-2026-55436 [HIGH] CWE-295 Coder's AI Bridge Proxy skips TLS certificate verification in default configuration Coder's AI Bridge Proxy skips TLS certificate verification in default configuration ### Summary The AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned a secure transport when an upstream proxy was configured. In the default configuration (no upstream proxy), outbound HTTPS to the Coder access URL acce
ghsa
CVE-2025-58437P3HIGH≥ 2.22.0, < 2.24.4≥ 2.25.0, < 2.25.22025-09-05
CVE-2025-58437 [HIGH] CWE-269 Coder vulnerable to privilege escalation could lead to a cross workspace compromise Coder vulnerable to privilege escalation could lead to a cross workspace compromise ## Summary Insecure session handling opened room for a privilege escalation scenario in which [prebuilt workspaces](https://coder.com/docs/admin/templates/extending-templates/prebuilt-workspaces) could be compromised by abusing a shared system identity. ## Details Coder automatically generates a s
ghsaosv
CVE-2026-45796P3MEDIUM≥ 2.33.0-rc.0, < 2.33.3≥ 2.32.0-rc.0, < 2.32.2+4 more2026-05-19
CVE-2026-45796 [MEDIUM] CWE-918 Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint ## Summary Unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submitting a crafted PKCS#7 signature. The ser
ghsa
CVE-2026-55078P3MEDIUM≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55078 [MEDIUM] CWE-409 Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service ### Summary `POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer. > **Note:** Exploitation requires authenticated file-upload acc
ghsa
CVE-2026-55434P3MEDIUM≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.82026-07-06
CVE-2026-55434 [MEDIUM] CWE-770 Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints ### Summary AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an authenticated user with AI Bridge access could send an arbitrarily large body and exhaust memory. > **Note:** Exploitation requires authenticated access to the AI B
ghsa
CVE-2026-55079P3MEDIUM≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55079 [MEDIUM] CWE-789 Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service ### Summary `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unco
ghsa
CVE-2026-55435P3MEDIUM≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+1 more2026-07-06
CVE-2026-55435 [MEDIUM] CWE-863 Suspended Coder users retain access to AI Bridge LLM proxy endpoints Suspended Coder users retain access to AI Bridge LLM proxy endpoints ### Summary AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps wor
ghsa
CVE-2026-55438P4MEDIUM≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55438 [MEDIUM] CWE-346 Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing ### Summary Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment parsed as a UUID, the workspace was resolved by ID without confirming the URL's username matched the real owner, while the CORS middleware t
ghsa
CVE-2026-55430P4MEDIUM≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55430 [MEDIUM] CWE-345 Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access ### Summary The workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the hea
ghsa
CVE-2026-55433P4MEDIUM≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55433 [MEDIUM] CWE-862 Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers ### Summary The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. > *
ghsa
CVE-2026-55432P4MEDIUM≥ 2.34.0, < 2.34.2≥ 2.33.0, < 2.33.8+2 more2026-07-06
CVE-2026-55432 [MEDIUM] CWE-862 Coder's sub-agent app registration bypasses template port-sharing policy enforcement Coder's sub-agent app registration bypasses template port-sharing policy enforcement ### Summary The `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum. > **Note:** Exploitation requires the ability to register s
ghsa
Github.Com Coder Coder V2 vulnerabilities | cvebase