blob: 47b99545751fdaa31dbc6dfa508fc5c543992b93 [file]
id: GO-2026-6267
modules:
- module: github.com/coder/coder
vulnerable_at: 0.27.3
- module: github.com/coder/coder/v2
versions:
- fixed: 2.29.17
- introduced: 2.30.0
- fixed: 2.32.7
- introduced: 2.33.0
- fixed: 2.33.8
- introduced: 2.34.0
- fixed: 2.34.2
vulnerable_at: 2.34.1
summary: |-
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL
appearance settings in github.com/coder/coder
ghsas:
- GHSA-h58c-xccx-75m3
references:
- advisory: https://github.com/coder/coder/security/advisories/GHSA-h58c-xccx-75m3
- fix: https://github.com/coder/coder/commit/ec19bc41d80568c0eb9f74b526e8cc8ffbe3be9a
- fix: https://github.com/coder/coder/pull/25804
- web: https://github.com/coder/coder/releases/tag/v2.29.17
- web: https://github.com/coder/coder/releases/tag/v2.32.7
- web: https://github.com/coder/coder/releases/tag/v2.33.8
- web: https://github.com/coder/coder/releases/tag/v2.34.2
source:
id: GHSA-h58c-xccx-75m3
created: 2026-08-24T21:20:57.250057-04:00
review_status: UNREVIEWED