vulns.co
/
GKData.io MCP

Coder · 2 min read

Coder: privileged provisioning must preserve existing object ownership

CVE-2026-55429 concerns a provisioning update-or-insert operation that could change an existing workspace application’s ownership relationship without checking the existing workspace. The maintainer describes potential redirection of subsequent application traffic across workspace boundaries under elevated provisioning authority.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: privileged service execution is not evidence that every referenced object belongs to the initiating workspace. Enforce ownership invariants at the mutation boundary, including collision/update behavior. The maintainer patch rejects cross-workspace reassignment while preserving legitimate same-workspace rebuilds and initial claims of unowned objects.

Before reading

  • Basic understanding of server-side object authorization and resource ownership

Context and limits

  • The maintainer requires elevated access as a template author or external provisioner operator. The stated consequence is application-traffic redirection, including IDE or terminal sessions; no customer incident, measured data loss, or independent reproduction is established here.
  • The advisory credits Anthropic’s Security Team for independent disclosure (ANT-2026-22441); the listed author is the advisory publisher account.
  • The advisory lists patched software versions 2.34.2, 2.33.8, 2.32.7, and 2.29.17 and no workaround. Release v2.34.2 independently links this fix. Pull request 26103 merged June 11, 2026; this merge date is not a resource edition date or a deployment date.
  • The maintainer pull request describes regression coverage for ownership transitions, including same-workspace rebuilds and unowned object claims. This review did not execute those tests or establish that any installation is upgraded. No award evidence is supplied.

Sources and provenance

  1. Workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID Coder · reviewed 2026-10-03
  2. Prevent cross-tenant workspace app rebinding Coder · reviewed 2026-10-03
  3. v2.34.2 security release Coder · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software