lowCVSS 3.4Vulnerability

GHSA-h58c-xccx-75m3

### Summary The `ApplicationName` and `LogoURL` appearance settings were rendered into HTML output without sufficient escaping which let a highly privileged Owner-role user inject HTML into the Coder dashboard and SMTP notification emails. > **Note:** Exploitation requires the `Owner` role which already holds full administrative control of the deployment so practical impact is limited. ### Impact An Owner-role user could store HTML markup in the `ApplicationName` or `LogoURL` appearance settings that later rendered in the dashboard and in SMTP notification emails which results in stored HTML injection against other users of the deployment. Exploitation requires the highly privileged `Owner` role. ### Patches The fix escapes the `ApplicationName` and `LogoURL` appearance values in HTML output before rendering. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds Restrict the `Owner` role to trusted administrators. ### References - Fix: #25804 ### Credits We'd like to thank Anthropic's Security Team (ANT-2026-22453) for independently disclosing this issue!

Properties

ghsa_id
GHSA-h58c-xccx-75m3
severity
low
summary
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
cvss_score
3.4
cve_id
GHSA-h58c-xccx-75m3
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-08-20T18:34:26Z
source_url
https://github.com/advisories/GHSA-h58c-xccx-75m3
ghsa_updated
2026-08-20T18:34:32Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/coder/coder/v2

AFFECTS (1)

[Software]go/github.com/coder/coder/v2

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-h58c-xccx-75m3 (CVSS 3.4) — Ninja Signal Threat Intelligence | Ninja Signal