Insertion of Sensitive Information into Log File Affecting github.com/coder/coder/agent package, versions >=0.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Insertion of Sensitive Information into Log File vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMCODERCODERAGENT-14176143
  • published4 Dec 2025
  • disclosed3 Dec 2025
  • creditUnknown

Introduced: 3 Dec 2025

NewCVE-2025-66411  (opens in a new tab)
CWE-532  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File due to logging as unsanitized plaintext. An attacker can gain unauthorized access to sensitive information and potentially escalate privileges by accessing unsanitized logs containing confidential environment variables.

Note: This is only exploitable if an attacker has local access to the workspace or to third-party systems where logs are stored.

Workaround

This vulnerability can be mitigated by disabling Workspace Agent Logs by setting the configuration option CODER_AGENT_LOGGING_HUMAN=/dev/null.

CVSS Base Scores

version 4.0
version 3.1