CVE-2026-55433: Coder: missing ActionUpdate check allows devcontainer wipe
GHSA-jqj2-x4c5-jfxm MEDIUMCoder's devcontainer recreate endpoint checked only read-level workspace access instead of the update-level check enforced on the sibling delete endpoint, letting any authenticated principal holding a read-only role like Template Admin or Org Template Admin trigger a destructive container rebuild. There is no confidentiality impact and CVSS lands at only 5.4, but the integrity and availability hit is real: uncommitted work inside the devcontainer is destroyed on every call, and repeated invocation turns this into a self-service denial-of-service against developer or AI-agent workspaces. There's no public exploit, no KEV listing, and no EPSS signal, and exploitation requires an existing foothold with workspace access — this is not an internet-facing zero-click bug. Upgrade to 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR) depending on your release line; there is no workaround, so patching is the only mitigation, and in the interim audit who holds Template Admin/Org Template Admin roles and watch for repeated recreate calls from non-owner accounts.
What is the risk?
Medium severity (CVSS 5.4, AV:N/AC:L/PR:L/UI:N/C:N/I:L/A:L) reflecting a straightforward, low-complexity exploitation path that nonetheless requires an existing authenticated low-privilege role with access to the target workspace — this is a privilege-escalation-within-authenticated-scope issue, not an unauthenticated remote bypass. No public exploit code, no Nuclei template, not in CISA KEV, and no EPSS score, so opportunistic mass exploitation is unlikely; the realistic threat is an insider, a compromised low-privilege account, or a disgruntled contractor with Template Admin access deliberately or accidentally wiping workspace state. Impact is confined to integrity/availability of the specific workspace's in-container state — no data exfiltration or code execution primitive is granted directly by this bug.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Anthropic Python | go | >= 2.34.0, < 2.34.2 | 2.34.2 |
Do you use Anthropic Python? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Patch immediately to the version matching your release line: 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR) — no workaround exists. Audit current role assignments and minimize the number of principals holding Template Admin or Org Template Admin roles, since those are the roles capable of triggering this bypass. After patching, monitor Coder audit logs for devcontainer recreate events initiated by non-owner accounts as a detection signal for prior abuse, and review any workspaces that experienced unexplained state loss before the patch was applied.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-55433?
Coder's devcontainer recreate endpoint checked only read-level workspace access instead of the update-level check enforced on the sibling delete endpoint, letting any authenticated principal holding a read-only role like Template Admin or Org Template Admin trigger a destructive container rebuild. There is no confidentiality impact and CVSS lands at only 5.4, but the integrity and availability hit is real: uncommitted work inside the devcontainer is destroyed on every call, and repeated invocation turns this into a self-service denial-of-service against developer or AI-agent workspaces. There's no public exploit, no KEV listing, and no EPSS signal, and exploitation requires an existing foothold with workspace access — this is not an internet-facing zero-click bug. Upgrade to 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR) depending on your release line; there is no workaround, so patching is the only mitigation, and in the interim audit who holds Template Admin/Org Template Admin roles and watch for repeated recreate calls from non-owner accounts.
Is CVE-2026-55433 actively exploited?
No confirmed active exploitation of CVE-2026-55433 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-55433?
Patch immediately to the version matching your release line: 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR) — no workaround exists. Audit current role assignments and minimize the number of principals holding Template Admin or Org Template Admin roles, since those are the roles capable of triggering this bypass. After patching, monitor Coder audit logs for devcontainer recreate events initiated by non-owner accounts as a detection signal for prior abuse, and review any workspaces that experienced unexplained state loss before the patch was applied.
What systems are affected by CVE-2026-55433?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, training pipelines.
What is the CVSS score for CVE-2026-55433?
CVE-2026-55433 has a CVSS v3.1 base score of 5.4 (MEDIUM). The EPSS exploitation probability is 0.39%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0012 Valid Accounts AML.T0029 Denial of AI Service AML.T0101 Data Destruction via AI Agent Tool Invocation Compliance Controls Affected
What are the technical details?
Original Advisory
### Summary The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. > **Note:** Exploitation requires an existing low-privilege role with access to the target workspace. ### Impact Any authenticated principal with read-only workspace access, such as a Template Admin or Org Template Admin, could recreate a devcontainer, destroying uncommitted in-container state and, if called repeatedly, denying service. This is an authorization bypass leading to data loss and denial of service. ### Patches The fix adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds None. ### Resources - Fix: #25812 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22454) for independently disclosing this issue!
Exploitation Scenario
An organization grants a contractor or junior engineer a Template Admin role scoped for read-only template review. That account (or its credentials, if compromised) calls the devcontainer recreate API against a colleague's AI-agent development workspace, which lacked the ActionUpdate check present on the delete endpoint. The rebuild wipes uncommitted fine-tuning code and an in-progress agent session; the attacker repeats the call against multiple workspaces, denying service to the AI engineering team until the platform is patched and the offending role is revoked.
Weaknesses (CWE)
CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L References
Timeline
Related Vulnerabilities
CVE-2026-27775 8.8 Gitea: cached permission check allows repo takeover
Same package: anthropic CVE-2026-54449 8.8 LangBot: RCE via arbitrary STDIO MCP command
Same package: anthropic CVE-2026-7574 8.7 Claude Desktop: VM integrity bypass enables RCE
Same package: anthropic CVE-2026-55429 8.7 Coder: cross-workspace agent hijack via app ID reuse
Same package: anthropic CVE-2026-67428 8.5 Flyto2 Core: SSRF via unvalidated URLs in agent tools
Same package: anthropic