Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
Description
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the AgentLogLine dashboard component instantiated ansi-to-html without escapeXML: true and inserted the result via dangerouslySetInnerHTML so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters. Exploitation requires a victim to view attacker-controlled agent logs in the dashboard. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 enables escapeXML: true so HTML metacharacters are escaped before DOM insertion. No known workarounds are available.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/coder/coder/v2Go | >= 2.34.0, < 2.34.2 | 2.34.2 |
github.com/coder/coder/v2Go | >= 2.33.0, < 2.33.8 | 2.33.8 |
github.com/coder/coder/v2Go | >= 2.30.0, < 2.32.7 | 2.32.7 |
github.com/coder/coder/v2Go | < 2.29.17 | 2.29.17 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-7qw2-f75v-62f7ghsaADVISORY
- github.com/coder/coder/pull/25808ghsax_refsource_MISCWEB
- github.com/coder/coder/releases/tag/v2.29.17mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.32.7mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.33.8mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.34.2mitrex_refsource_MISC
- github.com/coder/coder/security/advisories/GHSA-7qw2-f75v-62f7ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.