CVE-2026-55433: Coder: missing ActionUpdate check allows devcontainer wipe

GHSA-jqj2-x4c5-jfxm MEDIUM
Published July 6, 2026
CISO Take

Coder's devcontainer recreate endpoint checked only read-level workspace access instead of the update-level check enforced on the sibling delete endpoint, letting any authenticated principal holding a read-only role like Template Admin or Org Template Admin trigger a destructive container rebuild. There is no confidentiality impact and CVSS lands at only 5.4, but the integrity and availability hit is real: uncommitted work inside the devcontainer is destroyed on every call, and repeated invocation turns this into a self-service denial-of-service against developer or AI-agent workspaces. There's no public exploit, no KEV listing, and no EPSS signal, and exploitation requires an existing foothold with workspace access — this is not an internet-facing zero-click bug. Upgrade to 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR) depending on your release line; there is no workaround, so patching is the only mitigation, and in the interim audit who holds Template Admin/Org Template Admin roles and watch for repeated recreate calls from non-owner accounts.

Sources: NVD GitHub Advisory

What is the risk?

Medium severity (CVSS 5.4, AV:N/AC:L/PR:L/UI:N/C:N/I:L/A:L) reflecting a straightforward, low-complexity exploitation path that nonetheless requires an existing authenticated low-privilege role with access to the target workspace — this is a privilege-escalation-within-authenticated-scope issue, not an unauthenticated remote bypass. No public exploit code, no Nuclei template, not in CISA KEV, and no EPSS score, so opportunistic mass exploitation is unlikely; the realistic threat is an insider, a compromised low-privilege account, or a disgruntled contractor with Template Admin access deliberately or accidentally wiping workspace state. Impact is confined to integrity/availability of the specific workspace's in-container state — no data exfiltration or code execution primitive is granted directly by this bug.

How does the attack unfold?

Initial Access
Attacker already holds an authenticated low-privilege role (Template Admin or Org Template Admin) with read-only access to the target workspace.
AML.T0012
Authorization Bypass
Attacker calls the devcontainer recreate endpoint, which only enforces an ActionRead check and omits the ActionUpdate check present on the sibling delete endpoint.
Destructive Rebuild
The devcontainer is rebuilt, destroying uncommitted in-container state such as fine-tuning code, datasets, or agent session data.
AML.T0101
Denial of Service
Repeated invocation of the recreate call against the same or multiple workspaces denies availability of AI development environments until patched.
AML.T0029

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Anthropic Python go >= 2.34.0, < 2.34.2 2.34.2
3.8K 5.2K dependents Pushed 3d ago 90% patched ~11d to patch Full package profile →

Do you use Anthropic Python? You're affected.

How severe is it?

CVSS 3.1
5.4 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 32% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Trivial

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR Low
UI None
S Unchanged
C None
I Low
A Low

What should I do?

1 step
  1. Patch immediately to the version matching your release line: 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR) — no workaround exists. Audit current role assignments and minimize the number of principals holding Template Admin or Org Template Admin roles, since those are the roles capable of triggering this bypass. After patching, monitor Coder audit logs for devcontainer recreate events initiated by non-owner accounts as a detection signal for prior abuse, and review any workspaces that experienced unexplained state loss before the patch was applied.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
Annex A.6 - Access control for AI system resources
OWASP LLM Top 10
LLM04 - Model Denial of Service

Frequently Asked Questions

What is CVE-2026-55433?

Coder's devcontainer recreate endpoint checked only read-level workspace access instead of the update-level check enforced on the sibling delete endpoint, letting any authenticated principal holding a read-only role like Template Admin or Org Template Admin trigger a destructive container rebuild. There is no confidentiality impact and CVSS lands at only 5.4, but the integrity and availability hit is real: uncommitted work inside the devcontainer is destroyed on every call, and repeated invocation turns this into a self-service denial-of-service against developer or AI-agent workspaces. There's no public exploit, no KEV listing, and no EPSS signal, and exploitation requires an existing foothold with workspace access — this is not an internet-facing zero-click bug. Upgrade to 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR) depending on your release line; there is no workaround, so patching is the only mitigation, and in the interim audit who holds Template Admin/Org Template Admin roles and watch for repeated recreate calls from non-owner accounts.

Is CVE-2026-55433 actively exploited?

No confirmed active exploitation of CVE-2026-55433 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-55433?

Patch immediately to the version matching your release line: 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR) — no workaround exists. Audit current role assignments and minimize the number of principals holding Template Admin or Org Template Admin roles, since those are the roles capable of triggering this bypass. After patching, monitor Coder audit logs for devcontainer recreate events initiated by non-owner accounts as a detection signal for prior abuse, and review any workspaces that experienced unexplained state loss before the patch was applied.

What systems are affected by CVE-2026-55433?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, training pipelines.

What is the CVSS score for CVE-2026-55433?

CVE-2026-55433 has a CVSS v3.1 base score of 5.4 (MEDIUM). The EPSS exploitation probability is 0.39%.

What is the AI security impact?

Affected AI Architectures

agent frameworkstraining pipelines

MITRE ATLAS Techniques

AML.T0012 Valid Accounts
AML.T0029 Denial of AI Service
AML.T0101 Data Destruction via AI Agent Tool Invocation

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: Annex A.6
OWASP LLM Top 10: LLM04

What are the technical details?

Original Advisory

### Summary The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. > **Note:** Exploitation requires an existing low-privilege role with access to the target workspace. ### Impact Any authenticated principal with read-only workspace access, such as a Template Admin or Org Template Admin, could recreate a devcontainer, destroying uncommitted in-container state and, if called repeatedly, denying service. This is an authorization bypass leading to data loss and denial of service. ### Patches The fix adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds None. ### Resources - Fix: #25812 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22454) for independently disclosing this issue!

Exploitation Scenario

An organization grants a contractor or junior engineer a Template Admin role scoped for read-only template review. That account (or its credentials, if compromised) calls the devcontainer recreate API against a colleague's AI-agent development workspace, which lacked the ActionUpdate check present on the delete endpoint. The rebuild wipes uncommitted fine-tuning code and an in-progress agent session; the attacker repeats the call against multiple workspaces, denying service to the AI engineering team until the platform is patched and the offending role is revoked.

Weaknesses (CWE)

CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Timeline

Published
July 6, 2026
Last Modified
July 8, 2026
First Seen
July 7, 2026

Related Vulnerabilities