CVE-2025-47269 | coder code-server up to 4.99.3 URL confused deputy (GHSA-p483-wpfp-42cj)
A vulnerability has been found in coder code-server up to 4.99.3 and classified as critical. This vulnerability affects unknown code of the component URL Handler. The manipulation leads to unintended intermediary.
This vulnerability was named CVE-2025-47269. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.