Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9qq-2qh5-8rxf

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

Summary

The CreateSubAgent RPC did not validate a requested app sharing level against the template's MaxPortSharingLevel before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum.

Note: Exploitation requires the ability to register sub-agent apps in a workspace the attacker controls.

Impact

A workspace owner with an agent token could register a sub-agent app as PUBLIC even when the template's MaxPortSharingLevel was owner, exposing the app to unauthenticated users via the wildcard app domain. This affected only deployments using Enterprise port-sharing policy and wildcard app hostnames and required an authenticated workspace owner with an agent token.

Patches

The fix clamps the sub-agent app sharing level to the template's MaxPortSharingLevel.

The fix was backported to all supported release lines:

Release linePatched version
2.34v2.34.2
2.33v2.33.8
2.32v2.32.7
2.29 (ESR)v2.29.17

Workarounds

Disable wildcard app hostnames (CODER_WILDCARD_ACCESS_URL) to block subdomain-based app routing.

Resources

  • Fix: #26061

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22452) for independently disclosing this issue!

Пакеты

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.34.0, < 2.34.2

2.34.2

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.33.0, < 2.33.8

2.33.8

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.30.0, < 2.32.7

2.32.7

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

< 2.29.17

2.29.17

EPSS

Процентиль: 24%
0.00315
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
2 месяца назад

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum. Exploitation requires the ability to register sub-agent apps in a workspace the attacker controls. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2clamps the sub-agent app sharing level to the template's `MaxPortSharingLevel`. As a workaround, disable wildcard app hostnames (`CODER_WILDCARD_ACCESS_URL`) to block subdomain-based app routing.

EPSS

Процентиль: 24%
0.00315
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862