coder records
28 published records for vendor coder.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-285 Improper Authorization2
- CWE-862 Missing Authorization2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-277 Insecure Inherited Permissions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
28 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2023-26114No exploit | Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.coder · code-server · CWE-1385 | Critical9.3 | — | 0.3% | Mar 23, 2023 |
36Monitor | CVE-2026-44454No exploit | Coder vulnerable to workspace auto-creation via crafted URL parameters without user consentcoder · coder · CWE-78 | High8.8 | — | 2.6% | Jul 7, 2026 |
36Monitor | CVE-2026-46354No exploit | Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theftcoder · coder · CWE-347 | Critical9.1 | — | 0.3% | Jul 7, 2026 |
34Monitor | CVE-2026-55429No exploit | Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app IDcoder · coder · CWE-639 | High8.7 | — | 0.5% | Jul 7, 2026 |
34Monitor | CVE-2026-35454No exploit | Code Extension Marketplace has a Zip Slip Path Traversalcoder · code-marketplace · CWE-22 | High8.7 | — | 0.4% | Apr 6, 2026 |
33Monitor | CVE-2026-55427No exploit | Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`coder · coder · CWE-74 | High8.3 | — | 0.5% | Jul 7, 2026 |
32Monitor | CVE-2024-27918No exploit | Coder's OIDC authentication allows email with partially matching domain to registercoder · coder · CWE-20 | High8.2 | — | 1.0% | Mar 20, 2024 |
32Monitor | CVE-2026-55428No exploit | Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinatorcoder · coder · CWE-285 | High8.2 | — | 0.4% | Jul 7, 2026 |
32Monitor | CVE-2025-58437No exploit | Coder's privilege escalation vulnerability could lead to a cross workspace compromisecoder · coder · CWE-277 | High8.1 | — | 0.4% | Sep 5, 2025 |
30Monitor | CVE-2021-3810No exploit | Inefficient Regular Expression Complexity in cdr/code-servercoder · code-server · CWE-1333 | High7.5 | — | 1.3% | Sep 17, 2021 |
29Monitor | CVE-2026-55076No exploit | Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linkingcoder · coder · CWE-287 | High7.4 | — | 0.6% | Jul 7, 2026 |
29Monitor | CVE-2026-55075No exploit | Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypasscoder · coder · CWE-287 | High7.4 | — | 0.5% | Jul 7, 2026 |
29Monitor | CVE-2026-55436No exploit | Coder's AI Bridge Proxy skips TLS certificate verification in default configurationcoder · coder · CWE-295 | High7.4 | — | 0.3% | Jul 7, 2026 |
28Monitor | CVE-2026-55077No exploit | Coder: User-admin role can reset owner account passwordcoder · coder · CWE-285 | High7.2 | — | 0.6% | Jul 7, 2026 |
27Monitor | CVE-2026-55438No exploit | Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofingcoder · coder · CWE-346 | Medium6.8 | — | 0.2% | Jul 7, 2026 |
27Monitor | CVE-2026-55430No exploit | Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data accesscoder · coder · CWE-345 | Medium6.8 | — | 0.2% | Jul 7, 2026 |
26Monitor | CVE-2026-55079No exploit | Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of servicecoder · coder · CWE-789 | Medium6.5 | — | 0.6% | Jul 7, 2026 |
26Monitor | CVE-2026-55078No exploit | Coder: Zip upload decompression lacks aggregate size limit, enabling denial of servicecoder · coder · CWE-409 | Medium6.5 | — | 0.6% | Jul 7, 2026 |
26Monitor | CVE-2026-55434No exploit | Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpointscoder · coder · CWE-770 | Medium6.5 | — | 0.6% | Jul 7, 2026 |
26Monitor | CVE-2026-45796No exploit | Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpointcoder · coder · CWE-918 | Medium6.5 | — | 0.4% | Jul 7, 2026 |
26Monitor | CVE-2025-59956No exploit | AgentAPI exposed user chat history via a DNS rebinding attackcoder · agentapi · CWE-350 | Medium6.5 | — | 0.4% | Sep 30, 2025 |
24Monitor | CVE-2021-42648No exploit | Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted Ucoder · code-server · CWE-79 | Medium6.1 | — | 0.8% | May 11, 2022 |
24Monitor | CVE-2026-55431No exploit | Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace appscoder · coder · CWE-522 | Medium6.1 | — | 0.3% | Jul 7, 2026 |
22Monitor | CVE-2025-66411No exploit | Coder logged sensitive objects unsanitizedcoder · coder · CWE-532 | Medium5.5 | — | 0.2% | Dec 3, 2025 |
21Monitor | CVE-2026-55433No exploit | Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containerscoder · coder · CWE-862 | Medium5.4 | — | 0.4% | Jul 7, 2026 |
- CVE-2023-2611437Monitor
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.
CriticalCVSS 9.3No exploitEPSS 0%coder · code-serverMar 23, 2023
- CVE-2026-4445436Monitor
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
HighCVSS 8.8No exploitEPSS 3%coder · coderJul 7, 2026
- CVE-2026-4635436Monitor
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
CriticalCVSS 9.1No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2026-5542934Monitor
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
HighCVSS 8.7No exploitEPSS 1%coder · coderJul 7, 2026
- CVE-2026-3545434Monitor
Code Extension Marketplace has a Zip Slip Path Traversal
HighCVSS 8.7No exploitEPSS 0%coder · code-marketplaceApr 6, 2026
- CVE-2026-5542733Monitor
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
HighCVSS 8.3No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2024-2791832Monitor
Coder's OIDC authentication allows email with partially matching domain to register
HighCVSS 8.2No exploitEPSS 1%coder · coderMar 20, 2024
- CVE-2026-5542832Monitor
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
HighCVSS 8.2No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2025-5843732Monitor
Coder's privilege escalation vulnerability could lead to a cross workspace compromise
HighCVSS 8.1No exploitEPSS 0%coder · coderSep 5, 2025
- CVE-2021-381030Monitor
Inefficient Regular Expression Complexity in cdr/code-server
HighCVSS 7.5No exploitEPSS 1%coder · code-serverSep 17, 2021
- CVE-2026-5507629Monitor
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
HighCVSS 7.4No exploitEPSS 1%coder · coderJul 7, 2026
- CVE-2026-5507529Monitor
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
HighCVSS 7.4No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2026-5543629Monitor
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
HighCVSS 7.4No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2026-5507728Monitor
Coder: User-admin role can reset owner account password
HighCVSS 7.2No exploitEPSS 1%coder · coderJul 7, 2026
- CVE-2026-5543827Monitor
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
MediumCVSS 6.8No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2026-5543027Monitor
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
MediumCVSS 6.8No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2026-5507926Monitor
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
MediumCVSS 6.5No exploitEPSS 1%coder · coderJul 7, 2026
- CVE-2026-5507826Monitor
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
MediumCVSS 6.5No exploitEPSS 1%coder · coderJul 7, 2026
- CVE-2026-5543426Monitor
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
MediumCVSS 6.5No exploitEPSS 1%coder · coderJul 7, 2026
- CVE-2026-4579626Monitor
Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint
MediumCVSS 6.5No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2025-5995626Monitor
AgentAPI exposed user chat history via a DNS rebinding attack
MediumCVSS 6.5No exploitEPSS 0%coder · agentapiSep 30, 2025
- CVE-2021-4264824Monitor
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted U
MediumCVSS 6.1No exploitEPSS 1%coder · code-serverMay 11, 2022
- CVE-2026-5543124Monitor
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
MediumCVSS 6.1No exploitEPSS 0%coder · coderJul 7, 2026
- CVE-2025-6641122Monitor
Coder logged sensitive objects unsanitized
MediumCVSS 5.5No exploitEPSS 0%coder · coderDec 3, 2025
- CVE-2026-5543321Monitor
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
MediumCVSS 5.4No exploitEPSS 0%coder · coderJul 7, 2026