CVE-2025-66411: Coder logged sensitive objects unsanitized

Published Dec 3, 2025
·
Updated

Summary Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized

Details By default Workspace Agent logs are redirected to stderr https://github.com/coder/coder/blob/a8862be546f347c59201e2219d917e28121c0edb/cli/agent.go#L432-L439

Workspace Agent Manifests containing sensitive environment variables were logged insecurely https://github.com/coder/coder/blob/7beb95fd56d2f790502e236b64906f8eefb969bd/agent/agent.go#L1090

An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs

This behavior opened room for unauthorized access and privilege escalation

Impact Impact varies depending on the environment variables set in a given workspace

Patches Fix was released & backported: - https://github.com/coder/coder/releases/tag/v2.28.4 - https://github.com/coder/coder/releases/tag/v2.27.7 - https://github.com/coder/coder/releases/tag/v2.26.5

Workarounds One potential workaround is to disable Workspace Agent Logs by setting following configuration option CODERAGENTLOGGINGHUMAN=/dev/null platform operators are advised to upgrade their deployments

Other sources

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs. This vulnerability is fixed in 2.26.5, 2.27.7, and 2.28.4.

MITRE

Affected Software

6 affected componentsFixes available
go/github.com/coder/coder/v2>=2.28.0<2.28.4
2.28.4
go/github.com/coder/coder/v2>=2.27.0<2.27.7
2.27.7
go/github.com/coder/coder/v2<2.26.5
2.26.5
Coder Coder Go<2.26.5
Coder Coder Go>=2.27.0<2.27.7
Coder Coder Go>=2.28.0<2.28.4

Event History

Dec 3, 2025
Advisory Published
via GitHub·04:28 PM
Data Sourced
via GitHub·04:28 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-66411?

CVE-2025-66411 is classified as a high severity vulnerability due to the exposure of sensitive values in plaintext logs.

2

How do I fix CVE-2025-66411?

To fix CVE-2025-66411, upgrade to a version of Workspace Agent that is 2.28.4 or later, or to 2.27.7 and ensure that sensitive data is appropriately sanitized before logging.

3

What versions are affected by CVE-2025-66411?

CVE-2025-66411 affects Workspace Agent versions from 2.27.0 to 2.28.4 and below 2.26.5.

4

What type of data is affected by CVE-2025-66411?

CVE-2025-66411 affects sensitive values that are logged in plaintext without proper sanitation.

5

Is CVE-2025-66411 exploitable in all environments?

CVE-2025-66411 is potentially exploitable in environments where Workspace Agent logging is enabled and monitored.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203