Executive brief
Coder, a platform for managing remote development environments, contained a flaw in how it verified user identities during login. An attacker could potentially take over a victim's account by exploiting a weakness in how the system confirms email addresses from third-party identity providers. This could lead to unauthorized access to sensitive development environments and corporate data.
Technical details
A vulnerability exists in Coder's OIDC implementation due to improper type assertion and insecure account linking logic. The OIDC callback used a Go type assertion for the 'email_verified' claim that failed open if the Identity Provider (IdP) returned a non-boolean value (like a string) or omitted the claim entirely. When combined with an unconditional email-based account fallback that matched users by email rather than a unique IdP subject, an attacker could register a victim's email at a malicious or misconfigured IdP to gain access to the victim's Coder account. The fix implements strict type coercion for the verification claim and restricts email-based fallback to first-time account linking only.
Affected products
- Coder Coder < 2.29.17, >= 2.30.0 < 2.32.7, >= 2.33.0 < 2.33.8, >= 2.34.0 < 2.34.2
Timeline
- 2026-05-27: other: Fixes submitted via pull requests
- 2026-06-12: patched: Security release v2.29.17 published
- 2026-07-07: disclosed: CVE published
References
- https://github.com/coder/coder/pull/25712
- https://github.com/coder/coder/pull/25713
- https://github.com/coder/coder/releases/tag/v2.29.17
- https://github.com/coder/coder/releases/tag/v2.32.7
- https://github.com/coder/coder/releases/tag/v2.33.8
- https://github.com/coder/coder/releases/tag/v2.34.2
- https://github.com/coder/coder/security/advisories/GHSA-75vm-6w67-gwvp