CVE-2026-63443
Last modified
CVE-2026-63443 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4.
Description
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's UUID can derive the victim's tailnet address and redirect control-plane requests to that agent. HTTP 301, 302, and 303 redirects can redirect read requests, while HTTP 307 and 308 preserve replayable write and process-start requests. The redirected workspace agent file APIs can read or write files as the victim workspace user, and affected versions exposing the workspace agent process API can execute commands after a redirected file write, crossing workspace and tenant boundaries. This issue is fixed in versions 2.29.19, 2.32.9, 2.33.10, and 2.34.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| coder | coder | >= 2.27.0, < 2.29.19; >= 2.30.0, < 2.32.9; >= 2.33.0, < 2.33.10; >= 2.34.0, < 2.34.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-63443?
How severe is CVE-2026-63443?
How do I fix CVE-2026-63443?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63429HeyForm is an open-source form builder. Prior to version 3.0…8.6
- CVE-2026-6343Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 1…4.3
- CVE-2026-63431Horilla is an HR and CRM software. In 1.5.0-85 and earlier, …6.5
- CVE-2026-63432Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 an…6.5
- CVE-2026-63435Mail is an internet library for Ruby designed to handle emai…5.3
- CVE-2026-6344The Fluent Forms plugin for WordPress is vulnerable to Arbit…4.9
- CVE-2026-63445Perses is an open-source dashboard and visualization project…7.1
- CVE-2026-63446Suricata is a network Intrusion Detection System, Intrusion …7.5
- CVE-2026-63447Suricata is a network Intrusion Detection System, Intrusion …7.5
- CVE-2026-63448Suricata is a network Intrusion Detection System, Intrusion …5.9
- CVE-2026-63449Suricata is a network Intrusion Detection System, Intrusion …3.7
- CVE-2026-6345Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 1…6.5
Are you affected by CVE-2026-63443?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
