We found results for “”
CVE-2025-66411
Good to know:
Date: December 3, 2025
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs. This vulnerability is fixed in 2.26.5, 2.27.7, and 2.28.4.
Severity Score
Related Resources (11)
Severity Score
Weakness Type (CWE)
Insertion of Sensitive Information into Log File
CWE-532Top Fix
Upgrade Version
Upgrade to version github.com/coder/coder/v2 - v2.26.5;github.com/coder/coder/v2 - v2.27.7;github.com/coder/coder/v2 - v2.28.4;https://github.com/coder/coder.git - v2.26.5;https://github.com/coder/coder.git - v2.27.7;https://github.com/coder/coder.git - v2.28.4
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | LOCAL |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


