Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-31619 | AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API. This allows for the unauthorized exfiltration of sensitive user data, specifically local message history, which can include secret keys, file system contents, and intellectual property the user was working on locally. This issue is fixed in version 0.4.0. | 
  Github GHSA | 
                GHSA-w64r-2g3w-w8w4 | Coder AgentAPI exposed user chat history via a DNS rebinding attack | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:coder:agentapi:*:*:*:*:*:*:*:* | 
Tue, 30 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | |
| Metrics | 
        
        ssvc
         
  | 
Tue, 30 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Coder
         Coder agentapi  | 
|
| Vendors & Products | 
        
        Coder
         Coder agentapi  | 
Tue, 30 Sep 2025 00:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API. This allows for the unauthorized exfiltration of sensitive user data, specifically local message history, which can include secret keys, file system contents, and intellectual property the user was working on locally. This issue is fixed in version 0.4.0. | |
| Title | AgentAPI exposed user chat history via a DNS rebinding attack | |
| Weaknesses | CWE-350 | |
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-30T14:14:53.214Z
Reserved: 2025-09-23T14:33:49.506Z
Link: CVE-2025-59956
Updated: 2025-09-30T14:14:47.754Z
Status : Analyzed
Published: 2025-09-30T11:37:41.743
Modified: 2025-10-08T15:05:53.100
Link: CVE-2025-59956
No data.
                        OpenCVE Enrichment
                    Updated: 2025-09-30T08:47:29Z
 EUVD
 Github GHSA