8.3
CVE-2026-63443
- EPSS 0.42%
- Veröffentlicht 15.09.2026 16:44:23
- Zuletzt bearbeitet 30.09.2026 17:51:36
- Erkennungen
Coder: Workspace agent API insecure redirect handling allowed cross-agent file read and write
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's UUID can derive the victim's tailnet address and redirect control-plane requests to that agent. HTTP 301, 302, and 303 redirects can redirect read requests, while HTTP 307 and 308 preserve replayable write and process-start requests. The redirected workspace agent file APIs can read or write files as the victim workspace user, and affected versions exposing the workspace agent process API can execute commands after a redirected file write, crossing workspace and tenant boundaries. This issue is fixed in versions 2.29.19, 2.32.9, 2.33.10, and 2.34.4.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellercoder
≫
Produkt
coder
Version
>= 2.27.0, < 2.29.19
Status
affected
Version
>= 2.30.0, < 2.32.9
Status
affected
Version
>= 2.33.0, < 2.33.10
Status
affected
Version
>= 2.34.0, < 2.34.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.36 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.3 | 2.8 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/coder/coder/security/advisories/GHSA-qrwj-vh9x-gw5v
https://github.com/coder/coder/pull/26600
https://github.com/coder/coder/pull/26611
https://github.com/coder/coder/pull/26612
https://github.com/coder/coder/pull/26613
https://github.com/coder/coder/pull/26622
https://github.com/coder/coder/commit/2312b67bc52c4e314c18c4b4be5dcf5500c94ad7
https://github.com/coder/coder/commit/812549d671d0f5a0b45adcee860d37b70aaddccd
https://github.com/coder/coder/commit/ec3ba84c0002f47dd979c073cde1ab345acbaea5
https://github.com/coder/coder/commit/eeb2624549ddb85538e493af3e678fdb185a809f
https://github.com/coder/coder/commit/f8bdec5add4711650d5bfb6ff93d0cc9d7821c81
https://github.com/coder/coder/releases/tag/v2.29.19
https://github.com/coder/coder/releases/tag/v2.32.9
https://github.com/coder/coder/releases/tag/v2.33.10
https://github.com/coder/coder/releases/tag/v2.34.4