Coder
Coder Code-server: vulnerabilidades y CVE
Coder Code-server tiene 5 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42302 | Crítica (9.8) | 1.3% | — | 8 may 2026 | FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The startup script… |
| CVE-2025-47269 | Alta (8.3) | 43% | — | 9 may 2025 | code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result in the attacker gaining access to the session token. Failure… |
| CVE-2023-26114 | Crítica (9.3) | 0.34% | — | 23 mar 2023 | Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and… |
| CVE-2021-42648 | Media (6.1) | 0.87% | — | 11 may 2022 | Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL. |
| CVE-2021-3810 | Alta (7.5) | 1.3% | — | 17 sept 2021 | code-server is vulnerable to Inefficient Regular Expression Complexity |