VYPR

Vendor CVEs

Coder

All CVEs

29 total · sorted by risk
  • CVE-2026-46354CriJul 7, 2026
    risk 0.52cvss 9.1epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never…

  • CVE-2025-47269HigMay 9, 2025
    risk 0.50cvss 8.3epss 0.43

    code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result in the attacker gaining access to the session token. Failure to properly validate the port for a proxy request can…

  • CVE-2026-44454HigJul 7, 2026
    risk 0.46cvss 8.1epss 0.01

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user…

  • CVE-2025-58437HigSep 6, 2025
    risk 0.46cvss 8.1epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a…

  • CVE-2024-27918HigMar 21, 2024
    risk 0.46cvss 8.2epss 0.01

    Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, and 2.8.4, a vulnerability in Coder's OIDC authentication could allow an attacker to bypass the `CODER_OIDC_EMAIL_DOMAIN` verification and create an account…

  • CVE-2023-26114HigMar 23, 2023
    risk 0.46cvss 8.2epss 0.00

    Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

  • CVE-2025-66411HigDec 3, 2025
    risk 0.44cvss 7.8epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace…

  • CVE-2021-3810HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.01

    code-server is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2026-45796MedJul 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint…

  • CVE-2026-35454MedApr 6, 2026
    risk 0.35cvss 6.5epss 0.00

    The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulnerability in coder/code-marketplace allowed a malicious VSIX file to write arbitrary files outside the extension directory. ExtractZip passed raw zip entry names…

  • CVE-2025-59956MedSep 30, 2025
    risk 0.35cvss 6.5epss 0.00

    AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API.…

  • CVE-2026-55435MedJul 7, 2026
    risk 0.28cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key…

  • CVE-2026-55438MedJul 8, 2026
    risk 0.00cvss 5.8epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment…

  • CVE-2026-55437MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via…

  • CVE-2026-55436HigJul 8, 2026
    risk 0.00cvss 7.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify:…

  • CVE-2026-55433MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling…

  • CVE-2026-55432MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting…

  • CVE-2026-55431HigJul 8, 2026
    risk 0.00cvss 7.7epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the…

  • CVE-2026-55430MedJul 8, 2026
    risk 0.00cvss 5.8epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real…

  • CVE-2026-55429HigJul 8, 2026
    risk 0.00cvss 8.7epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the…

  • CVE-2026-55428HigJul 8, 2026
    risk 0.00cvss 8.2epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to…

  • CVE-2026-55427HigJul 8, 2026
    risk 0.00cvss 8.3epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without…

  • CVE-2026-55079MedJul 8, 2026
    risk 0.00cvss 4.9epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied…

  • CVE-2026-55078MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a…

  • CVE-2026-55077HigJul 7, 2026
    risk 0.00cvss 7.2epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting…

  • CVE-2026-55076HigJul 7, 2026
    risk 0.00cvss 7.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean…

  • CVE-2026-55075HigJul 7, 2026
    risk 0.00cvss 7.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chained into account takeover. Email-based user matching fell back to linking by email without checking…

  • CVE-2026-55434MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an authenticated user with AI…

  • CVE-2021-42648MedMay 11, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.