high

CVE-2026-55427

Go · github.com/coder/coder/v2

Summary

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Severity
high
CVSS
8.3
EPSS
0.5% (p39)
CWE
CWE-74, CWE-78
Also known as
GHSA-mcqq-fqgf-rxwm
Published
2026-07-06
Updated
2026-07-06

Advisory details

Summary

coder config-ssh wrote server-supplied SSH settings (HostnameSuffix, SSHConfigOptions) into the user's ~/.ssh/config without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration.

Note: Practical exploitation requires control of the server-supplied values through a malicious or compromised deployment, a man-in-the-middle position or admin access to the HostnameSuffix and SSHConfigOptions settings.

Impact

A server administrator or an attacker who controlled the server, could inject a directive such as ProxyCommand and achieve arbitrary code execution on any developer workstation that ran coder config-ssh. Injected commands ran with the local user's privileges and applied to all SSH connections, not just Coder workspaces.

Patches

The fix validates HostnameSuffix and SSHConfigOptions against a strict character set that rejects newlines and other control characters.

The fix was backported to all supported release lines:

Release line Patched version
2.34 v2.34.2
2.33 v2.33.8
2.32 v2.32.7
2.29 (ESR) v2.29.17

Workarounds

Inspect coder config-ssh --dry-run output before applying changes.

Resources

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22437) for independently disclosing this issue!

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.