CVE Alert: CVE-2025-47269

Vulnerability Summary: CVE-2025-47269
code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result in the attacker gaining access to the session token. Failure to properly validate the port for a proxy request can result in proxying to an arbitrary domain. The malicious URL `https://
Affected Endpoints:
No affected endpoints listed.
Published Date:
5/9/2025, 9:15:51 PM
🔥 CVSS Score:
Exploit Status:
Not ExploitedReferences:
- https://github.com/coder/code-server/commit/47d6d3ada5aadef6d221f3d612401eb3dad9299e
- https://github.com/coder/code-server/releases/tag/v4.99.4
- https://github.com/coder/code-server/security/advisories/GHSA-p483-wpfp-42cj
Recommended Action:
No proposed action available. Please refer to vendor documentation for updates.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.