CVE-2026-55432: Coder's sub-agent app registration bypasses template port-sharing policy enforcement
The CreateSubAgent RPC did not validate a requested app sharing level against the template’s MaxPortSharingLevel before persisting workspace apps, letting a workspace owner exceed the administrator’s configured maximum.
Note: Exploitation requires the ability to register sub-agent apps in a workspace the attacker controls.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55432 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →