VYPR
Moderate severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

CVE-2026-55433

Description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only ActionRead on the workspace and, unlike the sibling delete endpoint, performed no ActionUpdate check before triggering the destructive rebuild. Exploitation requires an existing low-privilege role with access to the target workspace. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds an explicit ActionUpdate authorization check before the agent is dialed like the delete endpoint. No known workarounds are available.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/coder/coder/v2Go
>= 2.34.0, < 2.34.22.34.2
github.com/coder/coder/v2Go
>= 2.33.0, < 2.33.82.33.8
github.com/coder/coder/v2Go
>= 2.30.0, < 2.32.72.32.7
github.com/coder/coder/v2Go
< 2.29.172.29.17

Affected products

1
  • Coder/Coderllm-fuzzy
    Range: <2.29.7, <2.32.7, <2.33.8, <2.34.2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.