Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55431— Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

CVSS 7.7 · High EPSS 0.18% · P8

Affected Version Matrix 4

VendorProductVersion RangeStatus
codercoder>= 2.34.0, < 2.34.2affected
>= 2.33.0, < 2.33.8affected
>= 2.30.0, < 2.32.7affected
< 2.29.17affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-55431

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
Source: CVE Program / CVE List V5
Vulnerability Description
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler. Practical exploitation requires the victim to run `coder open app` against a workspace whose external app definition the attacker controls. Only a malicious template author can control external app URLs. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a URL-scheme allowlist in the CLI and limits `$SESSION_TOKEN` substitution to trusted destinations like the web frontend. As a workaround, avoid running `coder open app` for untrusted workspaces.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
Source: CVE Program / CVE List V5
Vulnerability Title
Coder 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Coder是Coder组织开源的一个可以在公共或私有云基础设施中设置开发环境的应用程序。 Coder存在安全漏洞,该漏洞源于未验证外部工作空间应用URL的方案或主机,可能导致攻击者利用会话令牌泄露进行攻击。以下版本受到影响:2.29.17之前版本、2.32.7之前版本、2.33.8之前版本和2.34.2之前版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
codercoder >= 2.34.0, < 2.34.2 -

II. Public POCs for CVE-2026-55431

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55431

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55431 (1)

Vendor Advisories for CVE-2026-55431 (1)

Vendor Pages for CVE-2026-55431 (4)

Same Patch Batch · coder · 2026-07-08 · 8 CVEs total

CVE-2026-554298.7 HIGHCoder's workspace app upsert allows cross-workspace agent rebinding via user-controlled ap
CVE-2026-554367.4 HIGHCoder's AI Bridge Proxy skips TLS certificate verification in default configuration
CVE-2026-554385.8 MEDIUMCoder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
CVE-2026-554305.8 MEDIUMCoder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, en
CVE-2026-554375.4 MEDIUMCoder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine compone
CVE-2026-554325.4 MEDIUMCoder's sub-agent app registration bypasses template port-sharing policy enforcement
CVE-2026-554335.4 MEDIUMCoder: Devcontainer recreate endpoint missing write authorization allows read-only roles t

IV. Related Vulnerabilities

V. Comments for CVE-2026-55431

No comments yet


Leave a comment