mediumCVSS 5.4Vulnerability

CVE-2026-55433

### Summary The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. > **Note:** Exploitation requires an existing low-privilege role with access to the target workspace. ### Impact Any authenticated principal with read-only workspace access, such as a Template Admin or Org Template Admin, could recreate a devcontainer, destroying uncommitted in-container state and, if called repeatedly, denying service. This is an authorization bypass leading to data loss and denial of service. ### Patches The fix adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds None. ### Resources - Fix: #25812 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22454) for independently disclosing this issue!

Properties

severity
medium
summary
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
epss_score
0.00224
cvss_score
5.4
ghsa_published
2026-07-06T21:09:11Z
source_url
https://github.com/advisories/GHSA-jqj2-x4c5-jfxm
ghsa_updated
2026-07-06T21:09:13Z
ghsa_id
GHSA-jqj2-x4c5-jfxm
cve_id
CVE-2026-55433
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
is_ghsa_only
false
epss_percentile
0.13298

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/coder/coder/v2

AFFECTS (1)

[Software]go/github.com/coder/coder/v2

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55433 (CVSS 5.4) — Ninja Signal Threat Intelligence | Ninja Signal