CVE-2026-55433
### Summary The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. > **Note:** Exploitation requires an existing low-privilege role with access to the target workspace. ### Impact Any authenticated principal with read-only workspace access, such as a Template Admin or Org Template Admin, could recreate a devcontainer, destroying uncommitted in-container state and, if called repeatedly, denying service. This is an authorization bypass leading to data loss and denial of service. ### Patches The fix adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds None. ### Resources - Fix: #25812 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22454) for independently disclosing this issue!
Properties
- severity
- medium
- summary
- Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
- epss_score
- 0.00224
- cvss_score
- 5.4
- ghsa_published
- 2026-07-06T21:09:11Z
- source_url
- https://github.com/advisories/GHSA-jqj2-x4c5-jfxm
- ghsa_updated
- 2026-07-06T21:09:13Z
- ghsa_id
- GHSA-jqj2-x4c5-jfxm
- cve_id
- CVE-2026-55433
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- is_ghsa_only
- false
- epss_percentile
- 0.13298
Related Entities (5)
ENRICHED_BY (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph