Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mcqq-fqgf-rxwm

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.3

Описание

Coder vulnerable to SSH config injection via unsanitized server-supplied values in coder config-ssh

Summary

coder config-ssh wrote server-supplied SSH settings (HostnameSuffix, SSHConfigOptions) into the user's ~/.ssh/config without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration.

Note: Practical exploitation requires control of the server-supplied values through a malicious or compromised deployment, a man-in-the-middle position or admin access to the HostnameSuffix and SSHConfigOptions settings.

Impact

A server administrator or an attacker who controlled the server, could inject a directive such as ProxyCommand and achieve arbitrary code execution on any developer workstation that ran coder config-ssh. Injected commands ran with the local user's privileges and applied to all SSH connections, not just Coder workspaces.

Patches

The fix validates HostnameSuffix and SSHConfigOptions against a strict character set that rejects newlines and other control characters.

The fix was backported to all supported release lines:

Release linePatched version
2.34v2.34.2
2.33v2.33.8
2.32v2.32.7
2.29 (ESR)v2.29.17

Workarounds

Inspect coder config-ssh --dry-run output before applying changes.

Resources

  • Fix: #26154

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22437) for independently disclosing this issue!

Пакеты

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.34.0, < 2.34.2

2.34.2

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.33.0, < 2.33.8

2.33.8

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.30.0, < 2.32.7

2.32.7

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

< 2.29.17

2.29.17

EPSS

Процентиль: 39%
0.00466
Низкий

8.3 High

CVSS3

Дефекты

CWE-74
CWE-78

Связанные уязвимости

CVSS3: 8.3
nvd
2 месяца назад

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration. Practical exploitation requires control of the server-supplied values through a malicious or compromised deployment, a man-in-the-middle position or admin access to the `HostnameSuffix` and `SSHConfigOptions` settings. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `HostnameSuffix` and `SSHConfigOptions` against a strict character set that rejects newlines and other control characters. As a workaround, inspect `coder config-ssh --dry-run` output before applying changes.

EPSS

Процентиль: 39%
0.00466
Низкий

8.3 High

CVSS3

Дефекты

CWE-74
CWE-78