CyberRota Analysis
AI-GeneratedThe vulnerability affects the Coder CLI, which allows users to open external workspace-app URLs without proper validation of the URL scheme or host. This flaw can lead to unauthorized access to a user's session token if a victim executes `coder open app` on a workspace controlled by an attacker. Organizations using Coder prior to the specified versions should prioritize patching to mitigate the risk of session hijacking, especially those utilizing untrusted workspace templates.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler. Practical exploitation requires the victim to run `coder open app` against a workspace whose external app definition the attacker controls. Only a malicious template author can control external app URLs. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a URL-scheme allowlist in the CLI and limits `$SESSION_TOKEN` substitution to trusted destinations like the web frontend. As a workaround, avoid running `coder open app` for untrusted workspaces.
Related CVEs
Other vulnerabilities affecting the same vendor(s)