Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrq8-fcv5-8hvp

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Summary

The tailnet coordinator validates that an agent's Addresses derive from its authenticated UUID but applies no equivalent check to AllowedIPs. The coordinator forwards agent-supplied AllowedIPs verbatim to tunnel peers which install them into the WireGuard peer configuration.

Impact

A malicious workspace agent can advertise arbitrary AllowedIPs prefixes including another agent's tailnet address. Coder's ServerTailnet routes to agents by tailnet IP so an agent that claims a victim's prefix can intercept web terminal and workspace app traffic and serve spoofed content. Exploitation requires an authenticated user with a running workspace and a modified agent binary.

Patches

The fix validates each AllowedIPs prefix against the authenticating agent's UUID just like Addresses.

The fix was backported to all supported release lines:

Release linePatched version
2.34v2.34.2
2.33v2.33.8
2.32v2.32.7
2.29 (ESR)v2.29.17

Workarounds

Operators who cannot upgrade immediately should monitor coordinator logs for agents advertising unexpected AllowedIPs prefixes.

Resources

  • Fix: #26144

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22451) for independently disclosing this issue!

Пакеты

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.34.0, < 2.34.2

2.34.2

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.33.0, < 2.33.8

2.33.8

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.30.0, < 2.32.7

2.32.7

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

< 2.29.17

2.29.17

EPSS

Процентиль: 34%
0.00405
Низкий

8.2 High

CVSS3

Дефекты

CWE-285
CWE-863

Связанные уязвимости

CVSS3: 8.2
nvd
2 месяца назад

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates each `AllowedIPs` prefix against the authenticating agent's UUID just like `Addresses`. As a workaround, monitor coordinator logs for agents advertising unexpected `AllowedIPs` prefixes.

EPSS

Процентиль: 34%
0.00405
Низкий

8.2 High

CVSS3

Дефекты

CWE-285
CWE-863