Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55431

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 7.7
CVSS3: 6.1
EPSS Низкий

Описание

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, coder open app opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the $SESSION_TOKEN placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler. Practical exploitation requires the victim to run coder open app against a workspace whose external app definition the attacker controls. Only a malicious template author can control external app URLs. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a URL-scheme allowlist in the CLI and limits $SESSION_TOKEN substitution to trusted destinations like the web frontend. As a workaround, avoid running coder open app for untrusted workspaces.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
Версия до 2.29.17 (исключая)
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
Версия от 2.30.0 (включая) до 2.32.7 (исключая)
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
Версия от 2.33.0 (включая) до 2.33.8 (исключая)
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
Версия от 2.34.0 (включая) до 2.34.2 (исключая)

EPSS

Процентиль: 27%
0.00336
Низкий

7.7 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 7.7
github
2 месяца назад

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

EPSS

Процентиль: 27%
0.00336
Низкий

7.7 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-522