| id: GO-2026-6267 |
| modules: |
| - module: github.com/coder/coder |
| vulnerable_at: 0.27.3 |
| - module: github.com/coder/coder/v2 |
| versions: |
| - fixed: 2.29.17 |
| - introduced: 2.30.0 |
| - fixed: 2.32.7 |
| - introduced: 2.33.0 |
| - fixed: 2.33.8 |
| - introduced: 2.34.0 |
| - fixed: 2.34.2 |
| vulnerable_at: 2.34.1 |
| summary: |- |
| Coder: Stored HTML injection via unescaped ApplicationName and LogoURL |
| appearance settings in github.com/coder/coder |
| ghsas: |
| - GHSA-h58c-xccx-75m3 |
| references: |
| - advisory: https://github.com/coder/coder/security/advisories/GHSA-h58c-xccx-75m3 |
| - fix: https://github.com/coder/coder/commit/ec19bc41d80568c0eb9f74b526e8cc8ffbe3be9a |
| - fix: https://github.com/coder/coder/pull/25804 |
| - web: https://github.com/coder/coder/releases/tag/v2.29.17 |
| - web: https://github.com/coder/coder/releases/tag/v2.32.7 |
| - web: https://github.com/coder/coder/releases/tag/v2.33.8 |
| - web: https://github.com/coder/coder/releases/tag/v2.34.2 |
| source: |
| id: GHSA-h58c-xccx-75m3 |
| created: 2026-08-24T21:20:57.250057-04:00 |
| review_status: UNREVIEWED |