Back to Database
Status published
Medium
CVE-2021-42648
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0,...
Vulnerability Description
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42648
Credits & Attribution
No credits recorded in the NVD database.
More from coder
View All →CVE-2025-66411
Coder logged sensitive objects unsanitized
High
7.8
CVE-2025-59956
AgentAPI exposed user chat history via a DNS rebinding attack
Medium
6.5
CVE-2025-58437
Coder's privilege escalation vulnerability could lead to a cross workspace compromise
High
8.1
CVE-2025-47269
code-server session cookie can be extracted by having user visit specially crafted proxy URL
High
8.3
CVE-2024-27918
Coder's OIDC authentication allows email with partially matching domain to register
High
8.2
Affected Vendor
coder
View all reports →Affected Software
code-server
Vulnerable Versions:
0
Timeline
Official Publish:
May 11th, 2022
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.