GHSA-h58c-xccx-75m3
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Quick fix
GHSA-h58c-xccx-75m3 — github.com/coder/coder/v2: upgrade to the fixed version with the command below.
go get github.com/coder/coder/v2@v2.34.2 Details
### Summary
The `ApplicationName` and `LogoURL` appearance settings were rendered into HTML output without sufficient escaping which let a highly privileged Owner-role user inject HTML into the Coder dashboard and SMTP notification emails.
> **Note:** Exploitation requires the `Owner` role which already holds full administrative control of the deployment so practical impact is limited.
### Impact
An Owner-role user could store HTML markup in the `ApplicationName` or `LogoURL` appearance settings that later rendered in the dashboard and in SMTP notification emails which results in stored HTML injection against other users of the deployment. Exploitation requires the highly privileged `Owner` role.
### Patches
The fix escapes the `ApplicationName` and `LogoURL` appearance values in HTML output before rendering.
The fix was backported to all supported release lines:
| Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) |
### Workarounds
Restrict the `Owner` role to trusted administrators.
### References
- Fix: #25804
### Credits
We'd like to thank Anthropic's Security Team (ANT-2026-22453) for independently disclosing this issue!
Are you affected?
Enter the version of the package you're using.
Affected packages
2.34.0 Fixed in: 2.34.2 go get github.com/coder/coder/v2@v2.34.2 2.33.0 Fixed in: 2.33.8 go get github.com/coder/coder/v2@v2.33.8 2.30.0 Fixed in: 2.32.7 go get github.com/coder/coder/v2@v2.32.7 0 Fixed in: 2.29.17 go get github.com/coder/coder/v2@v2.29.17 References
- https://github.com/coder/coder/security/advisories/GHSA-h58c-xccx-75m3 [WEB]
- https://github.com/coder/coder/pull/25804 [WEB]
- https://github.com/coder/coder/commit/ec19bc41d80568c0eb9f74b526e8cc8ffbe3be9a [WEB]
- https://github.com/coder/coder [PACKAGE]
- https://github.com/coder/coder/releases/tag/v2.29.17 [WEB]
- https://github.com/coder/coder/releases/tag/v2.32.7 [WEB]
- https://github.com/coder/coder/releases/tag/v2.33.8 [WEB]
- https://github.com/coder/coder/releases/tag/v2.34.2 [WEB]