Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-55075High· 7.4Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
CVE-2026-55077High· 7.2Coder: User-admin role can reset owner account password
Coder: User-admin role can reset owner account password
CVE-2026-55427High· 8.3Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
CVE-2026-55079Medium· 4.9Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
CVE-2026-55429High· 8.7Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
CVE-2026-55428High· 8.2Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
CVE-2026-55430Medium· 5.8Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
CVE-2026-55078Medium· 6.5Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
CVE-2026-55431High· 7.7Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
CVE-2026-55432Medium· 5.4Coder's sub-agent app registration bypasses template port-sharing policy enforcement
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
CVE-2026-55433Medium· 5.4Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
CVE-2026-55434Medium· 6.5Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
CVE-2026-55435Medium· 5.4Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
CVE-2026-55436High· 7.4Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
CVE-2026-55437Medium· 5.4Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
CVE-2026-55438Medium· 5.8Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
GHSA-vjc7-jrh9-9j86Critical· 10.09router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
CVE-2026-55615CriticalLangroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
CVE-2026-54496Critical· 9.3Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
CVE-2026-55790HighCraft CMS: DOM XSS via GitHub issue title in CraftSupport widget
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
CVE-2026-55792MediumCraft CMS: Sensitive File Disclosure / Server-Side File Read
Craft CMS: Sensitive File Disclosure / Server-Side File Read
CVE-2026-55793MediumCraft CMS: Stored XSS via Structure entry title in table view
Craft CMS: Stored XSS via Structure entry title in table view
CVE-2026-55794HighCraft CMS: Potential authenticated Remote Code Execution via referrer redirect
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
CVE-2026-55500Critical· 9.99routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
CVE-2026-35342Low· 3.3mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
CVE-2026-35346Low· 3.3comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
CVE-2026-35373Low· 3.3ln: rejects non-UTF-8 source filenames in target-directory mode
ln: rejects non-UTF-8 source filenames in target-directory mode
CVE-2026-35355Medium· 6.3install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
CVE-2026-35343Low· 3.3cut: -s (only-delimited) ignored when delimiter is a newline
cut: -s (only-delimited) ignored when delimiter is a newline
CVE-2026-35356Medium· 6.3install -D: symlink race in directory creation allows arbitrary file overwrite
install -D: symlink race in directory creation allows arbitrary file overwrite