How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Critical Coder Signature Bypass Exposes Developer Keys and Tokens

calendar_today May 21, 2026 person Roi Nisimi domain orca-security

A critical vulnerability (CVE-2026-46354, CVSS 9.1) was disclosed affecting Coder, a popular open-source remote development platform, allowing attackers to steal workspace agent session tokens, Git SSH private keys, and OAuth credentials via a forged PKCS#7 signature bypass. Due to the unauthenticated nature of the attack and the breadth of potential secret exposure, immediate patching is […] The post Critical Coder Signature Bypass Exposes Developer Keys and Tokens appeared first on Orca Security .

open_in_new Read original post