Coder是Coder组织开源的一个可以在公共或私有云基础设施中设置开发环境的应用程序。 Coder存在加密问题漏洞,该漏洞源于AI Bridge Proxy的默认传输设置将 设置为true,导致当未配置上游代理时,出站HTTPS接受任何TLS证书,可能允许中间人攻击者进行攻击。以下版本受到影响:2.30.0版本至2.32.7之前版本、2.33.0版本至2.33.8之前版本和2.34.0版本至2.34.2之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55429 | 8.7 HIGH | Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled ap |
| CVE-2026-55431 | 7.7 HIGH | Coder's session token leaked to arbitrary hosts via `coder open app` for external workspac |
| CVE-2026-55438 | 5.8 MEDIUM | Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing |
| CVE-2026-55430 | 5.8 MEDIUM | Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, en |
| CVE-2026-55437 | 5.4 MEDIUM | Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine compone |
| CVE-2026-55432 | 5.4 MEDIUM | Coder's sub-agent app registration bypasses template port-sharing policy enforcement |
| CVE-2026-55433 | 5.4 MEDIUM | Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles t |
No comments yet