VYPR
High severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

CVE-2026-55431

Description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, coder open app opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the $SESSION_TOKEN placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler. Practical exploitation requires the victim to run coder open app against a workspace whose external app definition the attacker controls. Only a malicious template author can control external app URLs. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a URL-scheme allowlist in the CLI and limits $SESSION_TOKEN substitution to trusted destinations like the web frontend. As a workaround, avoid running coder open app for untrusted workspaces.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/coder/coder/v2Go
>= 2.34.0, < 2.34.22.34.2
github.com/coder/coder/v2Go
>= 2.33.0, < 2.33.82.33.8
github.com/coder/coder/v2Go
>= 2.30.0, < 2.32.72.32.7
github.com/coder/coder/v2Go
< 2.29.172.29.17

Affected products

1
  • Coder/Coderllm-fuzzy
    Range: <2.29.7, <2.32.7, <2.33.8, <2.34.2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.