AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-55431

HIGH · CVSS 7.7 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability affects the Coder CLI, which allows users to open external workspace-app URLs without proper validation of the URL scheme or host. This flaw can lead to unauthorized access to a user's session token if a victim executes `coder open app` on a workspace controlled by an attacker. Organizations using Coder prior to the specified versions should prioritize patching to mitigate the risk of session hijacking, especially those utilizing untrusted workspace templates.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55431
Severity
HIGH
CVSS
7.7
EPSS
0.18%

Original NVD Description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler. Practical exploitation requires the victim to run `coder open app` against a workspace whose external app definition the attacker controls. Only a malicious template author can control external app URLs. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a URL-scheme allowlist in the CLI and limits `$SESSION_TOKEN` substitution to trusted destinations like the web frontend. As a workaround, avoid running `coder open app` for untrusted workspaces.

Related CVEs

Other vulnerabilities affecting the same vendor(s)