CRITICAL 9.3 npm

code-server vulnerable to Missing Origin Validation in WebSockets

GHSA-frjg-g767-7363 · CVE-2023-26114

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

Ready to move

Start Securing

Free, no credit card | First findings in minutes