How to use this reference
Editorial lesson: privileged service execution is not evidence that every referenced object belongs to the initiating workspace. Enforce ownership invariants at the mutation boundary, including collision/update behavior. The maintainer patch rejects cross-workspace reassignment while preserving legitimate same-workspace rebuilds and initial claims of unowned objects.
Before reading
- Basic understanding of server-side object authorization and resource ownership
Context and limits
- The maintainer requires elevated access as a template author or external provisioner operator. The stated consequence is application-traffic redirection, including IDE or terminal sessions; no customer incident, measured data loss, or independent reproduction is established here.
- The advisory credits Anthropic’s Security Team for independent disclosure (ANT-2026-22441); the listed author is the advisory publisher account.
- The advisory lists patched software versions 2.34.2, 2.33.8, 2.32.7, and 2.29.17 and no workaround. Release v2.34.2 independently links this fix. Pull request 26103 merged June 11, 2026; this merge date is not a resource edition date or a deployment date.
- The maintainer pull request describes regression coverage for ownership transitions, including same-workspace rebuilds and unowned object claims. This review did not execute those tests or establish that any installation is upgraded. No award evidence is supplied.
Sources and provenance
- Workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID Coder · reviewed 2026-10-03
- Prevent cross-tenant workspace app rebinding Coder · reviewed 2026-10-03
- v2.34.2 security release Coder · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.