database

package

Versions in this module

v2
Aug 25, 2026
Aug 25, 2026
Aug 17, 2026
Aug 4, 2026
Changes in this version
type AIBridgeToolUsage
type AIProvider
type ChatQueuedMessage
type CreateUserSecretParams
type GetChatCostSummaryRow
type GetChatsParams
type InsertAIBridgeToolUsageParams
type InsertAIProviderParams
type InsertChatMessagesParams
type InsertChatQueuedMessageParams
type InsertChatQueuedMessageWithCreatorParams
type InsertMCPServerConfigParams
type ListUserSecretsRow
type MCPServerConfig
type MCPServerUserToken
type UpdateAIBridgeInterceptionEndedParams
type UpdateAIProviderParams
type UpdateChatExecutionStateParams
type UpdateMCPServerConfigParams
type UpdateUserSecretByUserIDAndNameParams
type UserSecret
Aug 25, 2026
Aug 25, 2026
Aug 10, 2026
Jul 27, 2026
Jul 14, 2026
Jul 7, 2026
Jul 7, 2026
Changes in this version
type BoundaryLog
type BoundarySession
type ChatMessage
type ChatQueuedMessage
type ChatStatus
type CryptoKeyFeature
type GetUsersParams
type InsertBoundarySessionParams
type InsertGitSSHKeyParams
type InsertOrganizationParams
type InsertReplicaParams
type Organization
type Template
type TemplateTable
type UpdateChatLastTurnSummaryParams
type UpdateGitSSHKeyParams
type UpdateOrganizationParams
type UpdateReplicaParams
type UpdateTemplateScheduleByIDParams
type WorkspaceBuild
type WorkspaceBuildTable
Aug 10, 2026
Jul 27, 2026
Jul 14, 2026
Jun 30, 2026
Jun 27, 2026
Jun 17, 2026 GO-2026-5923
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Jun 11, 2026 GO-2026-5923
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Jun 8, 2026 GO-2026-5906 +19 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 2, 2026 GO-2026-5906 +19 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type ChatMessage
type ChatModelConfig
type ChatQueuedMessage
type CountAIBridgeInterceptionsParams
type CountAIBridgeSessionsParams
type InsertChatMessagesParams
type InsertChatModelConfigParams
type InsertChatQueuedMessageParams
type InsertMCPServerConfigParams
type ListAIBridgeInterceptionsParams
type ListAIBridgeSessionsParams
type MCPServerConfig
type UpdateAIBridgeInterceptionEndedParams
type UpdateChatModelConfigParams
type UpdateMCPServerConfigParams
Apr 29, 2026
Jun 29, 2026
Jun 27, 2026
Jun 17, 2026 GO-2026-5923
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Jun 11, 2026 GO-2026-5923
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Jun 8, 2026 GO-2026-5906 +19 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 23, 2026 GO-2026-5906 +19 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 19, 2026 GO-2026-5906 +19 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 18, 2026 GO-2026-5906 +19 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 13, 2026 GO-2026-5906 +19 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 7, 2026 GO-2026-5169 +21 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 6, 2026 GO-2026-5169 +21 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 5, 2026 GO-2026-5169 +21 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5921: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type ChatMode
type ChatQueuedMessage
type ChatStatus
type GetChatMessagesByChatIDDescPaginatedParams
type GetProvisionerJobsByOrganizationAndStatusWithQueuePositionAndProvisionerRow
type GetUserChatSpendInPeriodParams
type InsertAIBridgeInterceptionParams
type InsertChatQueuedMessageParams
type InsertMCPServerConfigParams
type ListAIBridgeSessionsRow
type MCPServerConfig
type UpdateMCPServerConfigParams
Apr 22, 2026 GO-2026-5169 +1 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Apr 15, 2026 GO-2026-5169 +1 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Apr 8, 2026 GO-2026-5169 +1 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Apr 1, 2026 GO-2026-5169 +1 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Jun 30, 2026
Jun 27, 2026
Jun 17, 2026 GO-2026-5923
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Jun 11, 2026 GO-2026-5923
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Jun 8, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 30, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 19, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 18, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 13, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 28, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 14, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type AIBridgeToolUsage
type CreateUserSecretParams
type GetDefaultProxyConfigRow
type GetUserStatusCountsParams
type GetUsersParams
type GroupMember
type InsertAIBridgeTokenUsageParams
type InsertAIBridgeToolUsageParams
type InsertUserParams
type ResourceType
type UpdateOrganizationWorkspaceSharingSettingsParams
type UpsertConnectionLogParams
type UpsertDefaultProxyParams
type UserSecret
Mar 24, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 19, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 18, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 13, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 1, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 28, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 9, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 9, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 1, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 25, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 13, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 10, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 6, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 4, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 3, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type AIBridgeInterception
type CountAIBridgeInterceptionsParams
type GetAPIKeysByUserIDParams
type GetUsersParams
type GetWorkspacesParams
type InsertAIBridgeInterceptionParams
type InsertOAuth2ProviderAppCodeParams
type InsertWorkspaceAgentDevcontainersParams
type ListAIBridgeInterceptionsParams
type OAuth2ProviderAppCode
type Template
type TemplateTable
type UpdateTemplateMetaByIDParams
type WorkspaceAgentDevcontainer
Feb 23, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 18, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 13, 2026 GO-2026-5906 +18 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 9, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 1, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 25, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 16, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 3, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 23, 2026 GO-2026-5169 +20 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 10, 2026 GO-2026-5169 +21 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 3, 2026 GO-2026-5169 +21 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5920: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5925: Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type CheckConstraint
type CustomRolesParams
type ForeignKeyConstraint
type InsertCustomRoleParams
type Organization
type UpdateCustomRoleParams
type UpdateUserStatusParams
Jun 27, 2026
Jun 17, 2026 GO-2026-5923
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Jun 12, 2026 GO-2026-5923
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
May 30, 2026 GO-2026-5906 +16 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 19, 2026 GO-2026-5906 +16 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 18, 2026 GO-2026-5906 +16 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 13, 2026 GO-2026-5906 +16 more
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 1, 2026 GO-2026-5169 +18 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type UpdateExternalAuthLinkRefreshTokenParams
Apr 28, 2026 GO-2026-5169 +18 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 10, 2026 GO-2026-5169 +18 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type CountAuditLogsParams
type CountConnectionLogsParams
Mar 25, 2026 GO-2026-5169 +18 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 3, 2026 GO-2026-5169 +18 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 23, 2026 GO-2026-5169 +18 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 5, 2026 GO-2026-5169 +19 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 3, 2026 GO-2026-5169 +19 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 29, 2026 GO-2026-5169 +19 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 26, 2026 GO-2026-5169 +19 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 21, 2026 GO-2026-5169 +19 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 9, 2025 GO-2026-5169 +19 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 2, 2025 GO-2026-5169 +19 more
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type AIBridgeInterception
type GetPresetByIDRow
type GetTemplatePresetsWithPrebuildsRow
type GetWorkspaceAgentAndLatestBuildByAuthTokenRow
type InsertAIBridgeInterceptionParams
type InsertPresetParams
type InsertTaskParams
type TaskTable
type TemplateTable
type TemplateVersionPreset
type UpdateTemplateMetaByIDParams
Feb 23, 2026 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 3, 2026 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 29, 2026 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 26, 2026 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 20, 2026 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 9, 2025 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 1, 2025 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 27, 2025 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 12, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 11, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 10, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 4, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type AIBridgeInterception
type APIKeyScope
type GetProvisionerJobsByOrganizationAndStatusWithQueuePositionAndProvisionerParams
type GetWorkspacesRow
type ListAIBridgeInterceptionsParams
type ResourceType
type TaskWorkspaceApp
type Workspace
Jan 26, 2026 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 20, 2026 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 9, 2025 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 1, 2025 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 27, 2025 GO-2026-5897 +17 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 12, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 11, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 10, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 30, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 28, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 16, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 2, 2025 GO-2025-4182 +18 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5923: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type APIKeyScope
type GetTemplatesWithFilterParams
type InsertAPIKeyParams
type NotificationTemplateKind
type OrganizationMembersParams
type PaginatedOrganizationMembersParams
type UpsertWorkspaceAppParams
type WorkspaceApp
Dec 1, 2025 GO-2026-5897 +16 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 27, 2025 GO-2026-5897 +16 more
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 10, 2025 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 28, 2025 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 16, 2025 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 1, 2025 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Sep 3, 2025 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type ExternalAuthLink
type ForeignKeyConstraint
type GetProvisionerDaemonsWithStatusByOrganizationParams
type GetWorkspacesParams
type InsertProvisionerJobParams
type InsertTemplateParams
type ProvisionerJob
type Template
type TemplateTable
type TemplateVersion
type TemplateVersionTable
type UpdateExternalAuthLinkRefreshTokenParams
type UpdateTemplateMetaByIDParams
type WorkspaceBuild
type WorkspaceBuildTable
Oct 1, 2025 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Sep 3, 2025 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 7, 2025 GO-2025-3938 +18 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 5, 2025 GO-2025-3938 +18 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetPresetByIDRow
type InsertOAuth2ProviderAppTokenParams
type InsertPresetParams
type InsertTemplateParams
type TemplateVersionPreset
May 14, 2026 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 13, 2026 GO-2025-4182 +17 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Sep 4, 2025 GO-2025-4182 +19 more
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 7, 2025 GO-2025-3938 +20 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 15, 2025 GO-2025-3938 +20 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 2, 2025 GO-2025-3938 +20 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 1, 2025 GO-2025-3938 +20 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5911: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type AppSharingLevel
type GetPresetByIDRow
type GetTemplatePresetsWithPrebuildsRow
type GetTemplatesWithFilterParams
type GetWorkspacesEligibleForTransitionRow
type GetWorkspacesParams
type GetWorkspacesRow
type InsertPresetParams
type InsertTemplateVersionParameterParams
type TemplateVersion
type TemplateVersionParameter
type TemplateVersionPreset
type TemplateVersionTable
type WorkspaceAgent
type WorkspaceAppStatusState
Aug 7, 2025 GO-2025-3938 +19 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 15, 2025 GO-2025-3938 +19 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 8, 2025 GO-2025-3938 +19 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 30, 2025 GO-2025-3938 +19 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 10, 2025 GO-2025-3938 +19 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 3, 2025 GO-2025-3938 +19 more
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetPresetByIDRow
type GetProvisionerJobsByOrganizationAndStatusWithQueuePositionAndProvisionerRow
type GetTemplatePresetsWithPrebuildsRow
type GetWorkspacesRow
type InsertTemplateVersionTerraformValuesByJobIDParams
type InsertWorkspaceAppParams
type TemplateTable
type TemplateVersion
type TemplateVersionPreset
type UpdateTemplateMetaByIDParams
type VisibleUser
type Workspace
type WorkspaceApp
type WorkspaceBuild
May 20, 2025 GO-2025-3921 +20 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 15, 2025 GO-2025-3921 +20 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-3938: Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetUsersParams
type InsertWorkspaceAgentParams
type UniqueConstraint
type WorkspaceAgent
Apr 29, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 24, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 23, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetFailedWorkspaceBuildsByTemplateIDRow
Apr 2, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetProvisionerJobsByIDsWithQueuePositionRow
type GetUsersParams
type GetUsersRow
type GroupMember
type NotificationMethod
type OrganizationMembersParams
type UpdateUserAppearanceSettingsParams
type User
Apr 29, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 17, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 15, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 4, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetAuditLogsOffsetParams
type GetOrganizationsParams
type GetProvisionerDaemonsWithStatusByOrganizationParams
type GetProvisionerJobsByOrganizationAndStatusWithQueuePositionAndProvisionerParams
type InsertWorkspaceBuildParams
type Organization
type WorkspaceBuildTable
Apr 29, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 23, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetAuthorizationUserRolesRow
Mar 6, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 4, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetWorkspacesRow
type InsertWorkspaceAppParams
type InsertWorkspaceParams
type NotificationTemplate
type UpdateWorkspaceAutostartParams
type Workspace
type WorkspaceApp
type WorkspaceTable
Jan 29, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 23, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 18, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 7, 2025 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 16, 2024 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 3, 2024 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type AcquireProvisionerJobParams
type ForeignKeyConstraint
type GetWorkspaceAgentScriptTimingsByBuildIDRow
type InsertTemplateVersionParams
type InsertUserLinkParams
type InsertWorkspaceResourceParams
type TemplateVersion
type TemplateVersionTable
type UpdateUserLinkParams
type UserLink
type WorkspaceResource
Dec 12, 2024 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 8, 2024 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 8, 2024 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Nov 4, 2024 GO-2025-3921 +19 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5916: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetWorkspaceAgentAndLatestBuildByAuthTokenRow
type InsertUserParams
type UpdateInactiveUsersToDormantRow
Oct 24, 2024 GO-2025-3921 +18 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 1, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type FetchNewMessageMetadataRow
type GetGroupsParams
type InsertWorkspaceAgentScriptsParams
type InsertWorkspaceAgentStatsParams
type InsertWorkspaceAppParams
type ProvisionerDaemon
type UpsertProvisionerDaemonParams
type WorkspaceAgentScript
type WorkspaceAgentStat
type WorkspaceApp
Oct 28, 2024 GO-2025-3921 +18 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 8, 2024 GO-2025-3921 +18 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 8, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 1, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Sep 3, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type AcquireNotificationMessagesRow
type EnqueueNotificationMessageParams
type FetchNewMessageMetadataRow
type GetTemplatesWithFilterParams
type GetWorkspacesParams
type NotificationMessage
type NotificationMessageStatus
Oct 24, 2024 GO-2025-3921 +18 more
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Sep 5, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 20, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 7, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 6, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type AcquireNotificationMessagesRow
type FetchNewMessageMetadataRow
type ForeignKeyConstraint
type GetUsersRow
type NotificationMessage
Aug 20, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 6, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 1, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 23, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 18, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 2, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetAuditLogsOffsetParams
type InsertOrganizationParams
type InsertUserParams
type Organization
type UpdateOrganizationParams
Aug 1, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 22, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jul 18, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 24, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 21, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 6, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 4, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 24, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jun 21, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 22, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 16, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 6, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
May 22, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 22, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 17, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 3, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 22, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 17, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Apr 5, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 19, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 12, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetWorkspacesParams
type InsertOAuth2ProviderAppSecretParams
type InsertTemplateParams
type InsertWorkspaceAgentMetadataParams
type InsertWorkspaceAgentParams
type InsertWorkspaceAppParams
type Organization
type ProvisionerDaemon
type UpdateTemplateMetaByIDParams
type UpdateTemplateScheduleByIDParams
type UpsertProvisionerDaemonParams
type WorkspaceAgent
type WorkspaceAgentMetadatum
type WorkspaceApp
Mar 9, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 4, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 15, 2024 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 12, 2024 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 7, 2024 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Feb 7, 2024 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mar 4, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 24, 2024 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 22, 2024 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Jan 19, 2024 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type GetUsersRow
type UpdateTemplateMetaByIDParams
type UpdateUserProfileParams
type User
Mar 4, 2024 GO-2024-3228 +19 more
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 21, 2023 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 14, 2023 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Dec 12, 2023 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type BuildReason
type GetTailnetTunnelPeerBindingsRow
type GetTemplatesWithFilterParams
type GetUsersRow
type GetWorkspacesParams
type InsertProvisionerDaemonParams
type InsertUserLinkParams
type ProvisionerDaemon
type RegisterWorkspaceProxyParams
type ResourceType
type Template
type TemplateTable
type UpdateTemplateAccessControlByIDParams
type UpdateUserLinkParams
type WorkspaceProxy
Nov 17, 2023 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type UpdateWorkspaceAgentStartupByIDParams
Oct 30, 2023 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type WorkspaceAgent
Oct 20, 2023 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 17, 2023 GO-2024-2602 +20 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2024-3228: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect') in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Oct 11, 2023 GO-2024-2602 +19 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type ExternalAuthLink
type GetTemplateVersionsByTemplateIDParams
type GetWorkspacesParams
type GetWorkspacesRow
type InsertExternalAuthLinkParams
type InsertWorkspaceParams
type TemplateVersion
type TemplateVersionTable
type UpdateExternalAuthLinkParams
Oct 4, 2023 GO-2024-2602 +19 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Sep 27, 2023 GO-2024-2602 +19 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version
type InsertWorkspaceAgentLogsParams
type WorkspaceAgentLog
Sep 5, 2023 GO-2024-2602 +19 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 28, 2023 GO-2024-2602 +19 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 24, 2023 GO-2024-2602 +19 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 23, 2023 GO-2024-2602 +19 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Aug 22, 2023 GO-2024-2602 +19 more
Alert  GO-2024-2602: Incorrect email domain verification in github.com/coder/coder
Alert  GO-2025-3921: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
Alert  GO-2025-4182: Coder logs sensitive objects unsanitized in github.com/coder/coder
Alert  GO-2026-5169: Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
Alert  GO-2026-5196: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
Alert  GO-2026-5897: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
Alert  GO-2026-5906: Coder: User-admin role can reset owner account password in github.com/coder/coder
Alert  GO-2026-5907: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
Alert  GO-2026-5908: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
Alert  GO-2026-5909: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
Alert  GO-2026-5913: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
Alert  GO-2026-5915: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
Alert  GO-2026-5917: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
Alert  GO-2026-5918: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
Alert  GO-2026-5919: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
Alert  GO-2026-5922: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
Alert  GO-2026-5924: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
Alert  GO-2026-5926: Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
Alert  GO-2026-6265: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Alert  GO-2026-6267: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Changes in this version

Other modules containing this package

github.com/coder/coder

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL