VYPR
Vendor

Coder

Products
7
CVEs
29
Across products
30
Status
Private

Products

7

Recent CVEs

29
View all 29 CVEs →
  • CVE-2026-46354CriJul 7, 2026
    risk 0.52cvss 9.1epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never…

  • CVE-2025-47269HigMay 9, 2025
    risk 0.50cvss 8.3epss 0.43

    code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result in the attacker gaining access to the session token. Failure to properly validate the port for a proxy request can…

  • CVE-2026-44454HigJul 7, 2026
    risk 0.46cvss 8.1epss 0.01

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user…

  • CVE-2025-58437HigSep 6, 2025
    risk 0.46cvss 8.1epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a…

  • CVE-2024-27918HigMar 21, 2024
    risk 0.46cvss 8.2epss 0.01

    Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, and 2.8.4, a vulnerability in Coder's OIDC authentication could allow an attacker to bypass the `CODER_OIDC_EMAIL_DOMAIN` verification and create an account…

  • CVE-2023-26114HigMar 23, 2023
    risk 0.46cvss 8.2epss 0.00

    Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

  • CVE-2025-66411HigDec 3, 2025
    risk 0.44cvss 7.8epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace…

  • CVE-2021-3810HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.01

    code-server is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2026-45796MedJul 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint…

  • CVE-2026-35454MedApr 6, 2026
    risk 0.35cvss 6.5epss 0.00

    The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulnerability in coder/code-marketplace allowed a malicious VSIX file to write arbitrary files outside the extension directory. ExtractZip passed raw zip entry names…

  • CVE-2025-59956MedSep 30, 2025
    risk 0.35cvss 6.5epss 0.00

    AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API.…

  • CVE-2026-55435MedJul 7, 2026
    risk 0.28cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key…

  • CVE-2026-55438MedJul 8, 2026
    risk 0.00cvss 5.8epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment…

  • CVE-2026-55437MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via…

  • CVE-2026-55436HigJul 8, 2026
    risk 0.00cvss 7.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify:…

  • CVE-2026-55433MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling…

  • CVE-2026-55432MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting…

  • CVE-2026-55431HigJul 8, 2026
    risk 0.00cvss 7.7epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the…

  • CVE-2026-55430MedJul 8, 2026
    risk 0.00cvss 5.8epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real…

  • CVE-2026-55429HigJul 8, 2026
    risk 0.00cvss 8.7epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the…