Executive brief
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Affected products
- Go github.com/coder/coder/v2
- Go github.com/coder/coder
Junglewise Threat Intelligence
Severity: info · Published 2026-08-25
Vendors: Go.
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder