mediumCVSS 5.4Vulnerability

CVE-2026-55435

### Summary AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. > **Note:** Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. ### Impact A suspended user with a previously issued long-lived token could continue calling AI Bridge LLM proxy endpoints, consuming paid provider resources billed to the deployment and, if injected MCP tools are enabled, invoking those tools. Access persists until the token expires, which may be months after suspension. ### Patches The fix makes AI Bridge authorization reject non-active users like the standard API key middleware. AI Bridge was introduced in v2.30.0. The v2.29 ESR line is not affected. The fix is available in the following releases: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | ### Workarounds On suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`. ### Resources - Fix: #26173 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22446) for independently disclosing this issue!

Properties

severity
medium
summary
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
epss_score
0.00196
cvss_score
5.4
ghsa_published
2026-07-06T21:11:20Z
source_url
https://github.com/advisories/GHSA-wqxv-w64v-5wh6
ghsa_updated
2026-07-07T22:17:57Z
ghsa_id
GHSA-wqxv-w64v-5wh6
cve_id
CVE-2026-55435
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
is_ghsa_only
false
epss_percentile
0.09663

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/coder/coder/v2

AFFECTS (1)

[Software]go/github.com/coder/coder/v2

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55435 (CVSS 5.4) — Ninja Signal Threat Intelligence | Ninja Signal