5.4
CVE-2026-55433
- EPSS 0.22%
- Veröffentlicht 08.07.2026 00:22:36
- Zuletzt bearbeitet 08.07.2026 19:39:45
- CVE-Watchlists
- Unerledigt
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. Exploitation requires an existing low-privilege role with access to the target workspace. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. No known workarounds are available.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.131 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/coder/coder/releases/tag/v2.32.7
https://github.com/coder/coder/releases/tag/v2.33.8
https://github.com/coder/coder/releases/tag/v2.34.2
https://github.com/coder/coder/releases/tag/v2.29.17
https://github.com/coder/coder/security/advisories/GHSA-jqj2-x4c5-jfxm
https://github.com/coder/coder/pull/25812