GHSA-h58c-xccx-75m3
### Summary The `ApplicationName` and `LogoURL` appearance settings were rendered into HTML output without sufficient escaping which let a highly privileged Owner-role user inject HTML into the Coder dashboard and SMTP notification emails. > **Note:** Exploitation requires the `Owner` role which already holds full administrative control of the deployment so practical impact is limited. ### Impact An Owner-role user could store HTML markup in the `ApplicationName` or `LogoURL` appearance settings that later rendered in the dashboard and in SMTP notification emails which results in stored HTML injection against other users of the deployment. Exploitation requires the highly privileged `Owner` role. ### Patches The fix escapes the `ApplicationName` and `LogoURL` appearance values in HTML output before rendering. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds Restrict the `Owner` role to trusted administrators. ### References - Fix: #25804 ### Credits We'd like to thank Anthropic's Security Team (ANT-2026-22453) for independently disclosing this issue!
Properties
- ghsa_id
- GHSA-h58c-xccx-75m3
- severity
- low
- summary
- Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
- cvss_score
- 3.4
- cve_id
- GHSA-h58c-xccx-75m3
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-08-20T18:34:26Z
- source_url
- https://github.com/advisories/GHSA-h58c-xccx-75m3
- ghsa_updated
- 2026-08-20T18:34:32Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph