CVE-2025-47269 describes a critical vulnerability in code-server versions prior to 4.99.4, where a maliciously crafted URL leveraging the proxy subpath can lead to session token exfiltration. By failing to properly validate proxy request ports, an attacker can redirect a user's browser to an arbitrary domain, including their own, thereby capturing the user's session cookie. This allows the attacker to gain full access to the code-server instance and the underlying machine as the user running code-server. The vulnerability carries a CVSS score of 8.3 (HIGH), indicating a high-impact threat with network-based attack vector and low attack complexity, requiring user interaction. Successful exploitation grants high confidentiality and integrity impact, and low availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Coder | Code-Server | < 4.99.4CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.