CVE-2026-44454General(coder / coder)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch coder coder systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted `dotfiles_uri` value (for example, one containing shell command substitution such as `$(...)`) could achieve command execution in their own workspace. The Create Workspace page's `mode=auto` deep links amplified this into a one-click attack: an attacker could craft a URL that prefilled `param.dotfiles_uri` and silently provisioned a workspace with the attacker-controlled value, with no explicit user confirmation. In versions 2.29.7 and 2.30.2, input validation was added to the dotfiles module to reject URIs and usernames containing special characters, and the unsafe `eval`/`sh -c` usage was removed. This eliminated the command injection at its source.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coder

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
coder

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-09: 2Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 207-09
Signal classification2 categories
General
150.0%
Patch
150.0%
Full discourse2 posts
  • Mohi@disismohi
    General

    If you run @coderhq for dev environments, you had a shell injection until this week. CVE-2026-44454. Here's what actually happened and what to check Thursday.

    Post summary

    CVE‑2026‑44454 is a shell injection flaw in CoderHQ dev environments that existed until recently; the post provides no PoC, exploit, patch, or active exploitation details.

    1000058
    71 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-44454 (CVSS 8.1) - Command injection in Coder dotfiles module allows arbitrary code execution in workspaces. Versions <2.29.7 & <2.30.2 affected. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/N55yrC4LIR

    Post summary

    The tweet announces a high‑severity command injection in Coder dotfiles module (CVE‑2026‑44454) with CVSS 8.1, lists affected versions, and urges an immediate patch.

    0000095
    70 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodercoder-go-

Explore more