Coder
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 29 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 17, 2021 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Monitor Coder in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.