Skip to content
Threat Feed

Vendor

Coder

11 briefs RSS
high advisory

Coder Workspace Agent API Insecure Redirect Handling Allows Cross-Agent File Access and RCE

An authenticated user can exploit insecure redirect handling in the Coder workspace agent API to redirect API requests from their modified agent to a victim's online agent, enabling unauthorized file read/write operations and potential remote command execution across workspace and tenant boundaries.

Coder < v2.34.4 +3 vulnerability rce file-manipulation coder server-side-request-forgery ghsa
2t
high advisory

Coder AI Bridge Proxy TLS Certificate Verification Bypass (CVE-2026-55436)

The AI Bridge Proxy (`aibridgeproxyd`) in Coder's platform, when running in its default configuration without an upstream proxy, failed to perform TLS certificate verification for outbound HTTPS connections to the Coder server (CVE-2026-55436), allowing an on-path attacker to intercept sensitive data including Coder session tokens, user-supplied API keys, and full request/response bodies.

AI Bridge Proxy +2 vulnerability man-in-the-middle tls data-exfiltration
3t
high advisory

Coder `coder open app` Session Token Leakage Vulnerability (CVE-2026-55431)

A high-severity vulnerability, CVE-2026-55431, in the Coder CLI's `coder open app` command allows malicious workspace template authors to exfiltrate user session tokens via crafted external app URLs, leading to full account impersonation.

coder/coder/v2 +3 credential-access vulnerability cli-exploitation token-leakage coder
1t 1i
high advisory

Coder's Workspace App Vulnerability Allows Cross-Workspace Agent Rebinding

A critical authorization bypass vulnerability (CVE-2026-55429) exists in Coder's workspace application, allowing an attacker with template authorship or external provisioner access to rebind a victim's workspace app to their own agent, enabling them to proxy and compromise the victim's IDE and terminal sessions.

Coder +3 vulnerability privilege-escalation application
4t
high advisory

Coder Tailnet Vulnerability (CVE-2026-55428) Leads to Route Hijacking

A high-severity vulnerability (CVE-2026-55428) in Coder's tailnet coordinator allows a malicious workspace agent to hijack network routes by advertising arbitrary `AllowedIPs` prefixes, enabling interception and spoofing of web terminal and workspace application traffic.

Coder >= 2.34.0, < 2.34.2 +3 vulnerability cve route-hijacking network-attack supply-chain
1t
high advisory

Coder OIDC email_verified Type Coercion Bypass (CVE-2026-55076)

A vulnerability, CVE-2026-55076, in Coder's OpenID Connect (OIDC) authentication callback allowed an attacker to bypass email verification due to improper Go boolean type assertion of the `email_verified` claim, leading to full account takeover for existing user accounts.

Coder < 2.29.17 +3 account-takeover oidc vulnerability web-application
3t
high advisory

Coder OIDC Account Takeover Vulnerabilities (CVE-2026-55075)

Two critical flaws in Coder's OIDC login mechanism, CVE-2026-55075, allow an attacker to achieve account takeover by exploiting email-based user matching without proper IdP subject checks and bypassing the `email_verified` claim, leading to full access to victim workspaces and resources.

Coder < 2.29.17 +3 oidc account-takeover vulnerability coder cloud
2t
high advisory

Coder User-Admin Role Can Reset Owner Account Password (CVE-2026-55077)

A critical vulnerability, CVE-2026-55077, in the Coder platform allowed a user with the `user-admin` role to reset the password of an `owner` account without needing the current password via the `PUT /api/v2/users/{user}/password` endpoint, leading to privilege escalation and full deployment control.

Coder +3 privilege-escalation web-vulnerability api-vulnerability
1t
high advisory

Coder SSH Config Injection Vulnerability (CVE-2026-55427)

A malicious or compromised Coder server can exploit CVE-2026-55427 to inject unsanitized SSH configuration values via `coder config-ssh` into developer workstations, enabling arbitrary code execution on client machines.

Coder +3 ssh configuration-injection rce supply-chain developer-tools vulnerability
1t
high advisory

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

A command injection vulnerability (CVE-2026-44454) in the Coder platform's `dotfiles` module allows arbitrary code execution in a user's workspace, exploitable via a one-click attack using the `mode=auto` feature on the Create Workspace page that automatically provisions a workspace with a malicious `param.dotfiles_uri` without user consent, leading to immediate arbitrary code execution and potential data compromise or lateral movement.

coder/registry +3 command-injection rce web-application workspace cloud coder
1r 2t 2i
critical advisory

Coder Azure Instance Identity PKCS#7 Signature Bypass Leads to Unauthenticated Agent Token Theft (CVE-2026-46354)

Coder is vulnerable to a PKCS#7 signature bypass in Azure instance identity (CVE-2026-46354), allowing unauthenticated agent token theft via a forged vmId, enabling access to Git SSH private keys, OAuth access tokens, and workspace secrets.

Coder v2 +4 pkcs7 azure instance identity signature bypass unauthenticated access credential theft cve-2026-46354 coder
3r 3t