Coder vulnerable to SSH config injection via unsanitized server-supplied values in coder config-ssh in github.com/coder/coder
coder config-ssh
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2026-5913" }
"https://vuln.go.dev/ID/GO-2026-5913.json"