CVE-2025-58437

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-58437
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-58437.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-58437
Aliases
Downstream
Related
Published
2025-09-06T02:30:08Z
Modified
2025-10-10T17:52:36.631451Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Coder's privilege escalation vulnerability could lead to a cross workspace compromise
Details

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a user when a workspace is started. It is automatically exposed via coderworkspaceowner.session_token. Prebuilt workspaces are initially owned by a built-in prebuilds system user. When a prebuilt workspace is claimed, a new session token is generated for the user that claimed the workspace, but the previous session token for the prebuilds user was not expired. Any Coder workspace templates that persist this automatically generated session token are potentially impacted. This is fixed in versions 2.24.4 and 2.25.2.

References

Affected packages

Git / github.com/coder/coder

Affected ranges

Type
GIT
Repo
https://github.com/coder/coder
Events
Type
GIT
Repo
https://github.com/coder/coder
Events

Affected versions

v2.*

v2.25.0
v2.25.1