{"id":"CVE-2021-42648","details":"Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.","aliases":["GHSA-2gp3-6c9p-jp7w"],"modified":"2026-08-27T08:15:10.437799Z","published":"2022-05-11T18:15:23.097Z","related":["CGA-7rq7-f66g-9vw8"],"references":[{"type":"FIX","url":"https://github.com/cdr/code-server/issues/4355"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/coder/code-server","events":[{"introduced":"0"},{"fixed":"798dc0baf284416dbbf951e4ef596beeab6cb6c4"}],"database_specific":{"cpe":"cpe:2.3:a:coder:code-server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.12.0"}],"source":"CPE_RANGE"}}],"versions":["v3.9.1","3.4.1","3.4.0","v3.3.0","3.2.0","3.1.1","3.1.0","3.0.2","3.0.1","3.0.0","2.1698","2.1692-vsc1.39.2","2.1688-vsc1.39.2","2.1665-vsc1.39.2","2.1662-vsc1.39.2","2.1655-vsc1.39.2","2.1650-vsc1.39.2","2.1638-vsc1.39.2","2.1637-vsc1.39.2","2.1523-vsc1.38.1","2.1485-vsc1.38.1","2.1478-vsc1.38.1","2.1472-vsc1.38.1","1.1119-vsc1.33.1","1.1156-vsc1.33.1","1.1140-vsc1.33.1","1.1106-vsc1.33.1","1.1099-vsc1.33.1","1.939-vsc1.33.1","1.903-vsc1.33.1","1.868-vsc1.33.1","1.854-vsc1.33.1","1.792-vsc1.33.1","1.790-vsc1.33.1","1.696-vsc1.33.0","1.691-vsc1.33.0","1.604-vsc1.32.0","1.408-vsc1.32.0","1.32.0-310","1.32.0-282","1.32.0-275","1.32.0-245","1.31.1-100","1.31.0-20","1.31.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-42648.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}