DNS Rebinding Vulnerability in AgentAPI by Coder
CVE-2025-59956
What is CVE-2025-59956?
AgentAPI, an HTTP API for multiple coding tools such as Claude Code and Aider, is vulnerable to a client-side DNS rebinding attack when running over unprotected HTTP on localhost. This vulnerability enables attackers to exploit the /messages endpoint of the API, potentially leading to unauthorized access to sensitive information, including local message history, secret keys, and intellectual property. The security flaw is addressed in version 0.4.0 of AgentAPI, emphasizing the importance of keeping software up to date to mitigate such risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
agentapi < 0.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
