Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

coder — Vulnerabilities & Security Advisories 26

Browse all 26 CVE security advisories affecting coder. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This individual develops software applications with a primary focus on functionality and feature delivery. Historically, their code has been associated with multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, contributing to six CVEs. Their development practices often prioritize rapid implementation over secure coding, resulting in input validation weaknesses and improper access controls. While no major public security incidents have been directly linked to their work, the consistent pattern of vulnerabilities suggests systemic security gaps in their approach. Their codebase requires regular security reviews and remediation efforts to mitigate potential exploitation risks.

High2026-07-08
fix(coderd/workspaceapps): verify workspace owner matches app username by geokat · Pull Request #26085 · coder/coder · G
High2026-07-08
fix: base workspace-app CORS on resolved owner instead of URL username by geokat · Pull Request #26086 · coder/coder · G
MediumGHSA-22434-20262026-07-08
Workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing · Advisory · coder/coder · GitHub
HighANT-2026-224552026-07-08
AI Bridge Proxy skips TLS certificate verification in default configuration · Advisory · coder/coder · GitHub
High2026-07-08
fix!: only trust x-forwarded-host from configured trusted proxies by geokat · Pull Request #26204 · coder/coder · GitHub
High2026-07-08
fix: prevent session token exfiltration via external app URLs by zedkipp · Pull Request #26146 · coder/coder · GitHub
HighCVE-2025-034302026-07-08
Subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access · Advisor
HighCVE-2025-554312026-07-08
Session token leaked to arbitrary hosts via `coder open app` for external workspace apps · Advisory · coder/coder · GitH
MediumCVE-2026-554322026-07-08
Sub-agent app registration bypasses template port-sharing policy enforcement · Advisory · coder/coder · GitHub
MediumCVE-2026-554372026-07-08
Stored HTML injection via workspace agent logs in AgentLogLine component · Advisory · coder/coder · GitHub
High2026-07-08
fix: validate FileSize in NewDataBuilder to prevent OOM DoS by f0ssel · Pull Request #25710 · coder/coder · GitHub
High2026-07-08
fix(coderd): prevent cross-tenant workspace app rebinding by dylanhuff-at-coder · Pull Request #26103 · coder/coder · Gi
High2026-07-08
fix: validate agent-supplied AllowedIPs in coordinator by f0ssel · Pull Request #26144 · coder/coder · GitHub
High2026-07-08
fix!: validate HostnameSuffix and SSHConfigOptions' by johnstcn · Pull Request #26154 · coder/coder · GitHub
HighCVE-2025-54292026-07-08
Workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID · Advisory · coder/coder · GitHub
HighCVE-2025-54282026-07-08
Agent-supplied AllowedIPs not validated by tailnet coordinator allows route hijacking · Advisory · coder/coder · GitHub
HighGHSA-mcqq-lgfl-rxwm2026-07-08
SSH config injection via unsanitized server-supplied values in `coder config-ssh` · Advisory · coder/coder · GitHub
High2026-07-08
fix(coderd): prevent user-admin from resetting owner password by f0ssel · Pull Request #25709 · coder/coder · GitHub
HighCVE-2025-550772026-07-08
User-admin role can reset owner account password · Advisory · coder/coder · GitHub
High2026-07-08
fix: cap total zip expansion during tar conversion by geokat · Pull Request #25877 · coder/coder · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with coder. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.