Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55427

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, coder config-ssh wrote server-supplied SSH settings (HostnameSuffix, SSHConfigOptions) into the user's ~/.ssh/config without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration. Practical exploitation requires control of the server-supplied values through a malicious or compromised deployment, a man-in-the-middle position or admin access to the HostnameSuffix and SSHConfigOptions settings. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates HostnameSuffix and SSHConfigOptions against a strict character set that rejects newlines and other control characters. As a workaround, inspect coder config-ssh --dry-run output before applying changes.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
Версия до 2.29.17 (исключая)
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
Версия от 2.30.0 (включая) до 2.32.7 (исключая)
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
Версия от 2.33.0 (включая) до 2.33.8 (исключая)
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
Версия от 2.34.0 (включая) до 2.34.2 (исключая)

EPSS

Процентиль: 39%
0.00466
Низкий

8.3 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.3
github
2 месяца назад

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

EPSS

Процентиль: 39%
0.00466
Низкий

8.3 High

CVSS3

Дефекты

CWE-74