Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqj2-x4c5-jfxm

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

Summary

The devcontainer recreate endpoint relied on route middleware that checked only ActionRead on the workspace and, unlike the sibling delete endpoint, performed no ActionUpdate check before triggering the destructive rebuild.

Note: Exploitation requires an existing low-privilege role with access to the target workspace.

Impact

Any authenticated principal with read-only workspace access, such as a Template Admin or Org Template Admin, could recreate a devcontainer, destroying uncommitted in-container state and, if called repeatedly, denying service. This is an authorization bypass leading to data loss and denial of service.

Patches

The fix adds an explicit ActionUpdate authorization check before the agent is dialed like the delete endpoint.

The fix was backported to all supported release lines:

Release linePatched version
2.34v2.34.2
2.33v2.33.8
2.32v2.32.7
2.29 (ESR)v2.29.17

Workarounds

None.

Resources

  • Fix: #25812

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22454) for independently disclosing this issue!

Пакеты

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.34.0, < 2.34.2

2.34.2

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.33.0, < 2.33.8

2.33.8

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.30.0, < 2.32.7

2.32.7

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

< 2.29.17

2.29.17

EPSS

Процентиль: 32%
0.00394
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
2 месяца назад

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. Exploitation requires an existing low-privilege role with access to the target workspace. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. No known workarounds are available.

EPSS

Процентиль: 32%
0.00394
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862