CVE-2026-44454: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
(updated )
The dotfiles registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted dotfiles_uri value (for example, one containing shell command substitution such as $(...)) could achieve command execution in their own workspace. The Create Workspace page’s mode=auto deep links amplified this into a one-click attack: an attacker could craft a URL that prefilled param.dotfiles_uri and silently provisioned a workspace with the attacker-controlled value, with no explicit user confirmation.
References
- github.com/advisories/GHSA-m3cr-vc2j-pm27
- github.com/coder/coder/commit/60e3ab7632f42415d283b9fd5622ee53a4639ceb
- github.com/coder/coder/pull/22011
- github.com/coder/coder/releases/tag/v2.29.7
- github.com/coder/coder/releases/tag/v2.30.2
- github.com/coder/coder/security/advisories/GHSA-m3cr-vc2j-pm27
- github.com/coder/registry/commit/8e68c96633f65a1babd76a93b6923e3deead4a82
- github.com/coder/registry/pull/703
- nvd.nist.gov/vuln/detail/CVE-2026-44454
Code Behaviors & Features
Detect and mitigate CVE-2026-44454 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →