Junglewise Threat Intelligence

CVE-2026-19284: MauricioMilano coder-api command injection in project creation

CVE-2026-19284 · Severity: medium · CVSS 5.3 · Published 2026-08-08

Executive brief

MauricioMilano coder-api is a backend server that integrates with ChatGPT and Copilot to enable AI-assisted development tasks like creating and editing files. A command injection vulnerability in the project creation endpoint allows an attacker with local access to execute arbitrary system commands with the privileges of the running server process, potentially leading to full system compromise.

Technical details

The vulnerability is a command injection flaw in the createProject function (src/core/projects.ts) that accepts attacker-controlled Git parameters (branch, depth, url) and concatenates them directly into a shell command string executed via child_process.exec(). Because exec() invokes a shell interpreter rather than using a safer argument-array API, shell metacharacters in any of these fields can break out of the intended git clone syntax and inject arbitrary commands. An attacker must be able to reach the REST API endpoint POST /projects or invoke the MCP create-project tool; execution occurs with the privileges of the running coder-api process. The fix requires replacing exec() with spawn() or execFile(), plus strict input validation or allowlisting for branch, depth, and url parameters.

Affected products

  • MauricioMilano coder-api up to 1.1.0

Timeline

  • 2026-04-27: disclosed: Issue reported on GitHub
  • 2026-08-08: advisory: CVE-2026-19284 published

References