4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether code-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.3
CVE-2025-47269
code-server's session cookie can be extracted by having user visit specially crafted proxy URL
CRITICAL 9.3
CVE-2023-26114
code-server vulnerable to Missing Origin Validation in WebSockets
HIGH 7.5
CVE-2021-3810
Inefficient Regular Expression Complexity in code-server
MEDIUM 6.1
CVE-2021-42648
Cross site scripting in code-server
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes