5.4
CVE-2026-55435
- EPSS 0.2%
- Veröffentlicht 07.07.2026 17:37:31
- Zuletzt bearbeitet 09.07.2026 16:16:44
- CVE-Watchlists
- Unerledigt
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.095 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/coder/coder/security/advisories/GHSA-wqxv-w64v-5wh6
https://github.com/coder/coder/pull/26164
https://github.com/coder/coder/pull/26173
https://github.com/coder/coder/commit/0d2c9f904a8b75b888140fcc8fbf4633660cc787
https://github.com/coder/coder/releases/tag/v2.32.7
https://github.com/coder/coder/releases/tag/v2.33.8
https://github.com/coder/coder/releases/tag/v2.34.2