GHSA-9rjw-3gwp-f59v · Severity: high · Ecosystem: go — Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the authorization layer does not block the cross-workspace upsert. Exploitation requires elevated access as a template author or external provisioner operator. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 verifies that any existing `workspace_apps` row matching the supplied ID belongs to the workspace being built and rejects cross-workspace agent reassignment. No known workarounds are available.
Conclusion & alert: CVE-2026-55429 is rated Moderate Risk (48.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.52%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-07-08 | — | 0.52% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 3.1 | HIGH |
|
2.3 | 5.8 | [email protected] |
GHSA-9rjw-3gwp-f59v · Severity: high · Ecosystem: go — Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| coder | coder | < 2.29.17 | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* |
| coder | coder | >= 2.30.0, < 2.32.7 | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* |
| coder | coder | >= 2.33.0, < 2.33.8 | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* |
| coder | coder | >= 2.34.0, < 2.34.2 | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* |
| URL | Tags |
|---|---|
| https://github.com/coder/coder/pull/26103 | Issue Tracking Patch |
| https://github.com/coder/coder/releases/tag/v2.29.17 | Release Notes |
| https://github.com/coder/coder/releases/tag/v2.32.7 | Release Notes |
| https://github.com/coder/coder/releases/tag/v2.33.8 | Release Notes |
| https://github.com/coder/coder/releases/tag/v2.34.2 | Release Notes |
| https://github.com/coder/coder/security/advisories/GHSA-9rjw-3gwp-f59v | Patch Vendor Advisory |