Coder / Code-Server
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-47269 | code-server session cookie can be extracted by having user visit specially crafted proxy URL | HIGH | 8.3 | May 9, 2025 |
| CVE-2023-26114 | Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow… | CRITICAL | 9.3 | Mar 23, 2023 |
| CVE-2021-42648 | Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL. | MEDIUM | 6.1 | May 11, 2022 |
| CVE-2021-3810 | Inefficient Regular Expression Complexity in cdr/code-server | HIGH | 7.5 | Sep 17, 2021 |
Showing 1 to 4 of 4 CVEs