CVE-2026-63443
Coder: Workspace agent API insecure redirect handling allowed cross-agent file read and write
Description
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's UUID can derive the victim's tailnet address and redirect control-plane requests to that agent. HTTP 301, 302, and 303 redirects can redirect read requests, while HTTP 307 and 308 preserve replayable write and process-start requests. The redirected workspace agent file APIs can read or write files as the victim workspace user, and affected versions exposing the workspace agent process API can execute commands after a redirected file write, crossing workspace and tenant boundaries. This issue is fixed in versions 2.29.19, 2.32.9, 2.33.10, and 2.34.4.
INFO
Published Date :
Sept. 15, 2026, 5:17 p.m.
Last Modified :
Sept. 30, 2026, 5:51 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | [email protected] |
Solution
- Update Coder to version 2.29.19 or later.
- Update Coder to version 2.32.9 or later.
- Update Coder to version 2.33.10 or later.
- Update Coder to version 2.34.4 or later.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-63443.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-63443 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-63443
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-63443 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-63443 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 15, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-63443', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-09-15T17:31:25.407398Z'} -
New CVE Received by [email protected]
Sep. 15, 2026
Action Type Old Value New Value Added Description Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's UUID can derive the victim's tailnet address and redirect control-plane requests to that agent. HTTP 301, 302, and 303 redirects can redirect read requests, while HTTP 307 and 308 preserve replayable write and process-start requests. The redirected workspace agent file APIs can read or write files as the victim workspace user, and affected versions exposing the workspace agent process API can execute commands after a redirected file write, crossing workspace and tenant boundaries. This issue is fixed in versions 2.29.19, 2.32.9, 2.33.10, and 2.34.4. Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L Added CWE CWE-918 Added CWE CWE-863 Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/63xxx/CVE-2026-63443.json">CVE-2026-63443</a> Added Reference https://github.com/coder/coder/commit/2312b67bc52c4e314c18c4b4be5dcf5500c94ad7 Added Reference https://github.com/coder/coder/commit/812549d671d0f5a0b45adcee860d37b70aaddccd Added Reference https://github.com/coder/coder/commit/ec3ba84c0002f47dd979c073cde1ab345acbaea5 Added Reference https://github.com/coder/coder/commit/eeb2624549ddb85538e493af3e678fdb185a809f Added Reference https://github.com/coder/coder/commit/f8bdec5add4711650d5bfb6ff93d0cc9d7821c81 Added Reference https://github.com/coder/coder/pull/26600 Added Reference https://github.com/coder/coder/pull/26611 Added Reference https://github.com/coder/coder/pull/26612 Added Reference https://github.com/coder/coder/pull/26613 Added Reference https://github.com/coder/coder/pull/26622 Added Reference https://github.com/coder/coder/releases/tag/v2.29.19 Added Reference https://github.com/coder/coder/releases/tag/v2.32.9 Added Reference https://github.com/coder/coder/releases/tag/v2.33.10 Added Reference https://github.com/coder/coder/releases/tag/v2.34.4 Added Reference https://github.com/coder/coder/security/advisories/GHSA-qrwj-vh9x-gw5v