Coder是Coder组织开源的一个可以在公共或私有云基础设施中设置开发环境的应用程序。 Coder存在跨站脚本漏洞,该漏洞源于AgentLogLine仪表板组件在实例化ansi-to-html时未设置escapeXML: true,且服务端清理未中和HTML元字符,导致嵌入工作区代理日志行中的HTML呈现为活动标记,容易受到跨站脚本攻击。以下版本受到影响:2.29.17之前版本、2.30.0至2.32.7之前版本、2.33.0至2.33.8之前版本和2.34.0至2.34.2之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55429 | 8.7 HIGH | Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled ap |
| CVE-2026-55431 | 7.7 HIGH | Coder's session token leaked to arbitrary hosts via `coder open app` for external workspac |
| CVE-2026-55436 | 7.4 HIGH | Coder's AI Bridge Proxy skips TLS certificate verification in default configuration |
| CVE-2026-55438 | 5.8 MEDIUM | Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing |
| CVE-2026-55430 | 5.8 MEDIUM | Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, en |
| CVE-2026-55432 | 5.4 MEDIUM | Coder's sub-agent app registration bypasses template port-sharing policy enforcement |
| CVE-2026-55433 | 5.4 MEDIUM | Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles t |
No comments yet