← Volver al buscador de CVEs

CVE-2026-55438

Coder

Descripción

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder-s subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment parsed as a UUID, the workspace was resolved by ID without confirming the URL-s username matched the real owner, while the CORS middleware trusted the unverified username in the hostname. Practical exploitation requires subdomain app routing (wildcard hostname) enabled and a victim who visits the attacker-s crafted app URL while authenticated. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 validates the subdomain username against the resolved workspace-s actual owner and bases the same-owner CORS decision on the authoritative owner identity. No known workarounds are available.

CVSS 5.8EPSS 0.15%Riesgo 0.59
Ver fuente
Publicación
2026-07-08 01:16:28
Versiones afectadas
<2.29.17,<2.32.7,<2.33.8,<2.34.2
Tipo
Software crítico
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N