A AegiFlow
LOWCVSS 3.4

GHSA-h58c-xccx-75m3

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

Published
2026-08-20
Modified
2026-08-20
Sources
github-advisory

Summary

### Summary The `ApplicationName` and `LogoURL` appearance settings were rendered into HTML output without sufficient escaping which let a highly privileged Owner-role user inject HTML into the Coder dashboard and SMTP notification emails. > **Note:** Exploitation requires the `Owner` role which already holds full administrative control of the deployment so practical impact is limited. ### Impact An Owner-role user could store HTML markup in the `ApplicationName` or `LogoURL` appearance settings that later rendered in the dashboard and in SMTP notification emails which results in stored HTML injection against other users of the deployment. Exploitation requires the highly privileged `Owner` role. ### Patches The fix escapes the `ApplicationName` and `LogoURL` appearance values in HTML output before rendering. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds Restrict the `Owner` role to trusted administrators. ### References - Fix: #25804 ### Credits We'd like to thank Anthropic's Security Team (ANT-2026-22453) for independently disclosing this issue!

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/coder/coder/v22.34.2, 2.33.8, 2.32.7, 2.29.17

Remediation: Upgrade to 2.34.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.