« Volver al listado

CVE-2026-55437

Estado: AnalizadaMedia (5.4)—

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters. Exploitation requires a victim to view attacker-controlled agent logs in the dashboard. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 enables `escapeXML: true` so HTML metacharacters are escaped before DOM insertion. No known workarounds are available.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-55437",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-55437",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-08T14:00:28.554141Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "coder",
          "product": "coder",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.34.0, < 2.34.2"
            },
            {
              "status": "affected",
              "version": ">= 2.33.0, < 2.33.8"
            },
            {
              "status": "affected",
              "version": ">= 2.30.0, < 2.32.7"
            },
            {
              "status": "affected",
              "version": "< 2.29.17"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-08T01:16:28.020",
  "references": [
    {
      "url": "https://github.com/coder/coder/pull/25808",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/coder/coder/security/advisories/GHSA-7qw2-f75v-62f7",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters. Exploitation requires a victim to view attacker-controlled agent logs in the dashboard. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 enables `escapeXML: true` so HTML metacharacters are escaped before DOM insertion. No known workarounds are available."
    }
  ],
  "lastModified": "2026-07-08T19:38:48.677",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F97FAF48-192E-4814-82A5-085C44F1D261",
              "versionEndExcluding": "2.29.17"
            },
            {
              "criteria": "cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7ABD4A9B-6AE8-47D8-A1B7-91E42EE0481B",
              "versionEndExcluding": "2.32.7",
              "versionStartIncluding": "2.30.0"
            },
            {
              "criteria": "cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F759EEF3-6EAE-475B-85F8-38E7D7B47438",
              "versionEndExcluding": "2.33.8",
              "versionStartIncluding": "2.33.0"
            },
            {
              "criteria": "cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*",
              "vulnerable": true,
              "matchCriteriaId": "397A02BF-6CF6-40B1-B792-D7CB9D229050",
              "versionEndExcluding": "2.34.2",
              "versionStartIncluding": "2.34.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}