Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

coder — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting coder. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This individual develops software applications with a primary focus on functionality and feature delivery. Historically, their code has been associated with multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, contributing to six CVEs. Their development practices often prioritize rapid implementation over secure coding, resulting in input validation weaknesses and improper access controls. While no major public security incidents have been directly linked to their work, the consistent pattern of vulnerabilities suggests systemic security gaps in their approach. Their codebase requires regular security reviews and remediation efforts to mitigate potential exploitation risks.

CVE ID Title CVSS Severity Published
CVE-2026-63443 Coder: Workspace agent API insecure redirect handling allowed cross-agent file read and write — coder CWE-863 8.3 High 2026-09-15
CVE-2026-55438 Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing — coder CWE-346 5.8 Medium 2026-07-08
CVE-2026-55437 Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component — coder CWE-79 5.4 Medium 2026-07-08
CVE-2026-55436 Coder's AI Bridge Proxy skips TLS certificate verification in default configuration — coder CWE-295 7.4 High 2026-07-08
CVE-2026-55433 Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers — coder CWE-862 5.4 Medium 2026-07-08
CVE-2026-55432 Coder's sub-agent app registration bypasses template port-sharing policy enforcement — coder CWE-862 5.4 Medium 2026-07-08
CVE-2026-55431 Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps — coder CWE-522 7.7 High 2026-07-08
CVE-2026-55430 Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access — coder CWE-345 5.8 Medium 2026-07-08
CVE-2026-55429 Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID — coder CWE-639 8.7 High 2026-07-08
CVE-2026-55428 Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator — coder CWE-285 8.2 High 2026-07-07
CVE-2026-55427 Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` — coder CWE-74 8.3 High 2026-07-07
CVE-2026-55079 Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service — coder CWE-789 4.9 Medium 2026-07-07
CVE-2026-55078 Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service — coder CWE-409 6.5 Medium 2026-07-07
CVE-2026-55077 Coder: User-admin role can reset owner account password — coder CWE-285 7.2 High 2026-07-07
CVE-2026-55076 Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking — coder CWE-287 7.4 High 2026-07-07
CVE-2026-55075 Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass — coder CWE-287 7.4 High 2026-07-07
CVE-2026-46354 Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft — coder CWE-347 9.1 Critical 2026-07-07
CVE-2026-45796 Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint — coder CWE-918 6.5 Medium 2026-07-07
CVE-2026-44454 Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent — coder CWE-78 8.1 High 2026-07-07
CVE-2026-55434 Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints — coder CWE-770 6.5 Medium 2026-07-07
CVE-2026-55435 Suspended Coder users retain access to AI Bridge LLM proxy endpoints — coder CWE-863 5.4 Medium 2026-07-07
CVE-2026-35454 Code Extension Marketplace has a Zip Slip Path Traversal — code-marketplace CWE-22 6.2AI Medium AI 2026-04-06
CVE-2025-66411 Coder logged sensitive objects unsanitized — coder CWE-532 7.8 High 2025-12-03
CVE-2025-59956 AgentAPI exposed user chat history via a DNS rebinding attack — agentapi CWE-350 6.5 Medium 2025-09-29
CVE-2025-58437 Coder's privilege escalation vulnerability could lead to a cross workspace compromise — coder CWE-613 8.1 High 2025-09-06
CVE-2025-47269 code-server session cookie can be extracted by having user visit specially crafted proxy URL — code-server CWE-441 8.3 High 2025-05-09
CVE-2024-27918 Coder's OIDC authentication allows email with partially matching domain to register — coder CWE-20 8.2 High 2024-03-06

This page lists every published CVE security advisory associated with coder. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.