Skip to content
Noroxi

coder records

28 published records for vendor coder.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

28 records
  • Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.

    CriticalCVSS 9.3No exploitEPSS 0%

    coder · code-serverMar 23, 2023

  • Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

    HighCVSS 8.8No exploitEPSS 3%

    coder · coderJul 7, 2026

  • Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft

    CriticalCVSS 9.1No exploitEPSS 0%

    coder · coderJul 7, 2026

  • Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

    HighCVSS 8.7No exploitEPSS 1%

    coder · coderJul 7, 2026

  • Code Extension Marketplace has a Zip Slip Path Traversal

    HighCVSS 8.7No exploitEPSS 0%

    coder · code-marketplaceApr 6, 2026

  • Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

    HighCVSS 8.3No exploitEPSS 0%

    coder · coderJul 7, 2026

  • Coder's OIDC authentication allows email with partially matching domain to register

    HighCVSS 8.2No exploitEPSS 1%

    coder · coderMar 20, 2024

  • Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

    HighCVSS 8.2No exploitEPSS 0%

    coder · coderJul 7, 2026

  • Coder's privilege escalation vulnerability could lead to a cross workspace compromise

    HighCVSS 8.1No exploitEPSS 0%

    coder · coderSep 5, 2025

  • CVE-2021-3810
    30Monitor

    Inefficient Regular Expression Complexity in cdr/code-server

    HighCVSS 7.5No exploitEPSS 1%

    coder · code-serverSep 17, 2021

  • Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

    HighCVSS 7.4No exploitEPSS 1%

    coder · coderJul 7, 2026

  • Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

    HighCVSS 7.4No exploitEPSS 0%

    coder · coderJul 7, 2026

  • Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

    HighCVSS 7.4No exploitEPSS 0%

    coder · coderJul 7, 2026

  • Coder: User-admin role can reset owner account password

    HighCVSS 7.2No exploitEPSS 1%

    coder · coderJul 7, 2026

  • Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

    MediumCVSS 6.8No exploitEPSS 0%

    coder · coderJul 7, 2026

  • Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

    MediumCVSS 6.8No exploitEPSS 0%

    coder · coderJul 7, 2026

  • Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

    MediumCVSS 6.5No exploitEPSS 1%

    coder · coderJul 7, 2026

  • Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

    MediumCVSS 6.5No exploitEPSS 1%

    coder · coderJul 7, 2026

  • Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints

    MediumCVSS 6.5No exploitEPSS 1%

    coder · coderJul 7, 2026

  • Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint

    MediumCVSS 6.5No exploitEPSS 0%

    coder · coderJul 7, 2026

  • AgentAPI exposed user chat history via a DNS rebinding attack

    MediumCVSS 6.5No exploitEPSS 0%

    coder · agentapiSep 30, 2025

  • Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted U

    MediumCVSS 6.1No exploitEPSS 1%

    coder · code-serverMay 11, 2022

  • Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

    MediumCVSS 6.1No exploitEPSS 0%

    coder · coderJul 7, 2026

  • Coder logged sensitive objects unsanitized

    MediumCVSS 5.5No exploitEPSS 0%

    coder · coderDec 3, 2025

  • Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

    MediumCVSS 5.4No exploitEPSS 0%

    coder · coderJul 7, 2026