Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

coder — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in coder, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with Coder, an open-source developer environment platform, classified under common weakness types such as buffer overflow and improper input validation. It collects documented security flaws reported in Coder across the available advisory history, covering vulnerabilities published by the vendor and independent security researchers. Readers can use this aggregation to track the evolution of Coder’s security posture, understand the dominant classes of weaknesses affecting the product, and review the historical pattern of disclosures without needing to search individual advisory databases manually.

Vendor: coder

CVE ID Title CVSS Severity Published
CVE-2026-63443 Coder: Workspace agent API insecure redirect handling allowed cross-agent file read and write CWE-863 8.3 High 2026-09-15
CVE-2026-55438 Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing CWE-346 5.8 Medium 2026-07-08
CVE-2026-55437 Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component CWE-79 5.4 Medium 2026-07-08
CVE-2026-55436 Coder's AI Bridge Proxy skips TLS certificate verification in default configuration CWE-295 7.4 High 2026-07-08
CVE-2026-55433 Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers CWE-862 5.4 Medium 2026-07-08
CVE-2026-55432 Coder's sub-agent app registration bypasses template port-sharing policy enforcement CWE-862 5.4 Medium 2026-07-08
CVE-2026-55431 Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps CWE-522 7.7 High 2026-07-08
CVE-2026-55430 Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access CWE-345 5.8 Medium 2026-07-08
CVE-2026-55429 Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID CWE-639 8.7 High 2026-07-08
CVE-2026-55428 Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator CWE-285 8.2 High 2026-07-07
CVE-2026-55427 Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` CWE-74 8.3 High 2026-07-07
CVE-2026-55079 Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service CWE-789 4.9 Medium 2026-07-07
CVE-2026-55078 Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service CWE-409 6.5 Medium 2026-07-07
CVE-2026-55077 Coder: User-admin role can reset owner account password CWE-285 7.2 High 2026-07-07
CVE-2026-55076 Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking CWE-287 7.4 High 2026-07-07
CVE-2026-55075 Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass CWE-287 7.4 High 2026-07-07
CVE-2026-46354 Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft CWE-347 9.1 Critical 2026-07-07
CVE-2026-45796 Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint CWE-918 6.5 Medium 2026-07-07
CVE-2026-44454 Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent CWE-78 8.1 High 2026-07-07
CVE-2026-55434 Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints CWE-770 6.5 Medium 2026-07-07
CVE-2026-55435 Suspended Coder users retain access to AI Bridge LLM proxy endpoints CWE-863 5.4 Medium 2026-07-07
CVE-2025-66411 Coder logged sensitive objects unsanitized CWE-532 7.8 High 2025-12-03
CVE-2025-58437 Coder's privilege escalation vulnerability could lead to a cross workspace compromise CWE-613 8.1 High 2025-09-06
CVE-2024-27918 Coder's OIDC authentication allows email with partially matching domain to register CWE-20 8.2 High 2024-03-06

All 24 known CVE vulnerabilities affecting coder with full Chinese analysis, references, and POCs where available.