CVE-2025-58437HIGH 8.1EPSS p26.6%

CVE-2025-58437CVE-2025-58437

Description

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a user when a workspace is started. It is automatically exposed via coder_workspace_owner.session_token. Prebuilt workspaces are initially owned by a built-in prebuilds system user. When a prebuilt workspace is claimed, a new session token is generated for the user that claimed the workspace, but the previous session token for the prebuilds user was not expired. Any Coder workspace templates that persist this automatically generated session token are potentially impacted. This is fixed in versions 2.24.4 and 2.25.2.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS0.35% probability of exploitation · percentile 26.6% · 2026-06-19T12:03:05Z
Published2025-09-06
Last modified2025-10-17

Underlying weaknesses· 3

CWE-277CWE-279CWE-613

References

  1. https://github.com/coder/coder/commit/06cbb2890f453cd522bb2158a6549afa3419c276
  2. https://github.com/coder/coder/commit/20d67d7d7191a4fd5d36a61c6fc1e23ab59befc0
  3. https://github.com/coder/coder/commit/ec660907faa0b0eae20fa2ba58ce1733f5f4b35a
  4. https://github.com/coder/coder/pull/19667
  5. https://github.com/coder/coder/pull/19668
  6. https://github.com/coder/coder/pull/19669
  7. https://github.com/coder/coder/security/advisories/GHSA-j6xf-jwrj-v5qp

3

TypeTargetConfidenceTier
WeaknessInsecure Inherited Permissionscwe-2770%live
WeaknessIncorrect Execution-Assigned Permissionscwe-2790%live
WeaknessInsufficient Session Expirationcwe-6130%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-47269
CVE
CVE-2025-55345
CVE
CVE-2025-58372
CVE
CVE-2025-59823
CVE
CVE-2025-64660
CVE
CVE-2026-41613
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.