Junglewise Threat Intelligence

GO-2026-6267 - Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

Severity: info · Published 2026-08-25

Vendors: Go.

Executive brief

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

Affected products

  • Go github.com/coder/coder/v2
  • Go github.com/coder/coder

Related threats