Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-47269

43
FAUCET Score

CVE-2025-47269 describes a critical vulnerability in code-server versions prior to 4.99.4, where a maliciously crafted URL leveraging the proxy subpath can lead to session token exfiltration. By failing to properly validate proxy request ports, an attacker can redirect a user's browser to an arbitrary domain, including their own, thereby capturing the user's session cookie. This allows the attacker to gain full access to the code-server instance and the underlying machine as the user running code-server. The vulnerability carries a CVSS score of 8.3 (HIGH), indicating a high-impact threat with network-based attack vector and low attack complexity, requiring user interaction. Successful exploitation grants high confidentiality and integrity impact, and low availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.

Impacted Technologies

VendorProductVersion(s)CPE
CoderCode-Server
< 4.99.4CNA affected

CVSS Data

CVSS version used by this source: 3.1

8.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
36.03%
Probability of exploitation in next 30 days
EPSS Percentile
98.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.3603 is in the 99th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: code-serverFixed in: 4.99.4

Vendor Advisories (1)

npmGHSA-p483-wpfp-42cjhigh

code-server's session cookie can be extracted by having user visit specially crafted proxy URL

May 9, 2025

References

github.com / coder/code-server/commit/47d6d3ada5aadef6d221f3d612401eb3dad9299e
github.com / coder/code-server/releases/tag/v4.99.4
github.com / coder/code-server/security/advisories/GHSA-p483-wpfp-42cj