Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an authenticated user with AI Bridge access could send an arbitrarily large body and exhaust memory. Exploitation requires authenticated access to the AI Bridge endpoints and the impact is limited to availability (denial of service). Versions 2.33.8 and 2.34.2 patch the issue. No known workarounds are available.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-07-07
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted `dotfiles_uri` value (for example, one containing shell command substitution such as `$(...)`) could achieve command execution in their own workspace. The Create Workspace page's `mode=auto` deep links amplified this into a one-click attack: an attacker could craft a URL that prefilled `param.dotfiles_uri` and silently provisioned a workspace with the attacker-controlled value, with no explicit user confirmation. In versions 2.29.7 and 2.30.2, input validation was added to the dotfiles module to reject URIs and usernames containing special characters, and the unsafe `eval`/`sh -c` usage was removed. This eliminated the command injection at its source.
CVSS Score
8.1
EPSS Score
0.014
Published
2026-07-07
Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port, with no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malicious webpage to reach this API from any browser and write arbitrary content to the agent's persistent memory store, which the agent reads and acts on autonomously. Combined with execute_shell_command using shell=True, this creates a remote code execution chain requiring only that the victim visit a malicious webpage while Serena is running. This issue is fixed in version v1.5.2.
CVSS Score
8.3
EPSS Score
0.003
Published
2026-07-07
Improper validation leads to a generic XSS vector in the language override feature.
CVSS Score
5.9
EPSS Score
0.001
Published
2026-07-07
An improper access check allows unauthorized users to access workflow stage and transition information.
CVSS Score
6.4
EPSS Score
0.002
Published
2026-07-07
An improper access check allows users to display a list of modules in the frontend.
CVSS Score
6.4
EPSS Score
0.002
Published
2026-07-07
An improper access check allows unauthorized users to access com_privacy datasets.
CVSS Score
6.4
EPSS Score
0.002
Published
2026-07-07
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVSS Score
6.4
EPSS Score
0.003
Published
2026-07-07
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.
CVSS Score
5.4
EPSS Score
0.002
Published
2026-07-07
Lack of validation leads to an XSS vulnerability in the MFA management views.
CVSS Score
5.9
EPSS Score
0.001
Published
2026-07-07


Contact Us

Shodan ® - All rights reserved