UNKNOWN Go
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
GO-2026-5923 · CVE-2026-63443 · GHSA-qrwj-vh9x-gw5v
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Ready to move
Start Securing
Free, no credit card | First findings in minutes