CVE-2026-46354: Token theft in Coder, 9.1 rating 🔥
New vulnerability in Coder allows an attacker on any Azure VM to steal an agent session token, and with the stolen token get access to Git SSH private key, OAuth access tokens or workspace secrets.
Search at Netlas.io:
👉 Link: https://nt.ls/JwI80
👉 Dork: http.favicon.hash_sha256:05d85ef30160f0c790ba0acf9470dae35a85a90a2b79387fe4b6994852c1dbf4 OR http.meta:"https://coder.com/docs" OR http.unknon_headers.key:"x_coder_request_id" OR http.unknown_headers.key:"x_coder_build_version"
Vendor's advisory:
https://github.com/advisories/GHSA-6x44-w3xg-hqqf
Post #574
729

- 🔥 3
- ❤ 2