Vulnerabilities in coder

26 results
Vexday analysis

A base registra 26 vulnerabilidades no fornecedor Coder, com 20 publicadas nos últimos 90 dias, indicando atividade recente concentrada. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e apenas 1 é crítica em severidade, reduzindo o risco imediato. A fraqueza dominante é CWE-285 (controle de acesso impróprio), sugerindo que melhorias na autenticação e autorização devem ser priorizadas.

CVE-2025-47269HIGHcode-server session cookie can be extracted by having user visit specially crafted proxy URLEPSS 43.0%CVE-2026-44454HIGHCoder vulnerable to workspace auto-creation via crafted URL parameters without user consentEPSS 1.4%CVE-2024-27918HIGHCoder's OIDC authentication allows email with partially matching domain to registerEPSS 1.0%CVE-2025-59956MEDIUMAgentAPI exposed user chat history via a DNS rebinding attackEPSS 0.4%CVE-2025-58437HIGHCoder's privilege escalation vulnerability could lead to a cross workspace compromiseEPSS 0.4%CVE-2026-35454HIGHCode Extension Marketplace has a Zip Slip Path TraversalEPSS 0.3%CVE-2026-55078MEDIUMCoder: Zip upload decompression lacks aggregate size limit, enabling denial of serviceEPSS 0.3%CVE-2026-55079MEDIUMCoder's unbounded memory allocation in provisioner file upload allows authenticated denial of serviceEPSS 0.3%CVE-2026-55077HIGHCoder: User-admin role can reset owner account passwordEPSS 0.3%CVE-2026-45796MEDIUMCoder vulnerable to unauthenticated SSRF via Azure Instance Identity EndpointEPSS 0.3%CVE-2026-55434MEDIUMCoder vulnerable to denial of service via unbounded request body in AI Bridge provider endpointsEPSS 0.3%CVE-2026-55076HIGHCoder's OIDC email_verified type coercion bypass enables account takeover via unverified email linkingEPSS 0.3%CVE-2026-55429HIGHCoder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app IDEPSS 0.3%CVE-2026-55075HIGHCoder vulnerable to OIDC account takeover via email-based user matching and email_verified bypassEPSS 0.3%CVE-2026-55427HIGHCoder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`EPSS 0.3%CVE-2026-46354CRITICALCoder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theftEPSS 0.3%CVE-2026-55428HIGHCoder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinatorEPSS 0.2%CVE-2025-66411HIGHCoder logged sensitive objects unsanitizedEPSS 0.2%CVE-2026-55433MEDIUMCoder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containersEPSS 0.2%CVE-2026-55435MEDIUMSuspended Coder users retain access to AI Bridge LLM proxy endpointsEPSS 0.2%