CWE-1385— Missing Origin Validation in WebSockets
The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
43 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1385page 1 of 1
- CVE-2024-23168CRITICALCVSS 9.8EG 9.82024-08-15
Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.
- CVE-2014-125071CRITICALCVSS 5.5EG 9.82023-01-09
A vulnerability was found in lukehutch Gribbit. It has been classified as problematic. Affected is the function messageReceived of the file src/gribbit/request/HttpRequestHandler.java. The manipulation leads to missing origin validation in…
- CVE-2026-44211CRITICALCVSS 9.6EG 9.62026-06-01
Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly ava…
- CVE-2025-24964CRITICALCVSS 9.6EG 9.62025-02-04
Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. When…
- CVE-2023-0957CRITICALCVSS 8.2EG 9.62023-03-03
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s c…
- CVE-2024-48849CRITICALCVSS 9.4EG 9.42025-01-29
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.
- CVE-2026-85183CRITICALCVSS 9.3EG 9.32026-09-03
Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary…
- CVE-2026-35589CRITICALCVSS 9.3EG 9.32026-04-14
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-202…
- CVE-2026-71416HIGHCVSS 8.8EG 8.82026-09-11
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to th…
- CVE-2026-10054HIGHCVSS 8.8EG 8.82026-07-03
In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin vali…
- CVE-2025-52882HIGHCVSS 8.8EG 8.82025-06-24
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections …
- CVE-2023-49805HIGHCVSS 8.8EG 8.82023-12-11
Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to acces…
- CVE-2023-30856HIGHCVSS 8.3EG 8.32023-04-28
eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control webso…
- CVE-2023-26114HIGHCVSS 8.2EG 8.22023-03-23
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-…
- CVE-2026-59950HIGHCVSS 8.1EG 8.12026-07-15
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or …
- CVE-2026-34403HIGHCVSS 8.1EG 8.12026-04-20
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijackin…
- CVE-2025-54289HIGHCVSS 8.1EG 8.12025-10-02
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
- CVE-2023-2848HIGHCVSS 8.0EG 8.02023-09-14
Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a missing header validation.
- CVE-2023-2886HIGHCVSS 4.3EG 7.62023-05-25
Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
- CVE-2026-57111HIGHCVSS 7.5EG 7.52026-07-09
Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an auth…
- CVE-2026-15580MEDIUMCVSS 6.9EG 6.92026-08-21
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.
- CVE-2026-59804MEDIUMCVSS 6.8EG 6.82026-07-08
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active bridge sessions by opening a cross-orig…
- CVE-2026-44514MEDIUMCVSS 6.5EG 6.52026-05-14
Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user wi…
- CVE-2025-68930MEDIUMCVSS 6.5EG 6.52026-02-23
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during t…
- CVE-2025-56647MEDIUMCVSS 6.5EG 6.52026-02-12
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm…
- CVE-2026-22689MEDIUMCVSS 6.5EG 6.52026-01-10
Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept connections from any origin. This lack of Origin header validation introduces a Cross-Site WebSocket Hij…
- CVE-2025-24010MEDIUMCVSS 6.5EG 6.52025-01-20
Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket conn…
- CVE-2025-36116MEDIUMCVSS 6.3EG 6.32025-07-23
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSo…
- CVE-2026-1692MEDIUMCVSS 6.1EG 6.12026-02-26
A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote atta…
- CVE-2026-88061MEDIUMCVSS 5.8EG 5.82026-09-10
career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or re…
- CVE-2023-32264MEDIUMCVSS 5.8EG 5.82024-03-08
CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the client's computer.
- CVE-2026-13272MEDIUMCVSS 5.4EG 5.42026-09-14
IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
- CVE-2026-27977MEDIUMCVSS 5.4EG 5.42026-03-18
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass cas…
- CVE-2026-21883MEDIUMCVSS 5.4EG 5.42026-01-08
Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured with an allowlist (e.g., dashboard.corp), an attacker can register a domain like dashboard.corp.attacker.com (or use a …
- CVE-2024-8201MEDIUMCVSS 5.4EG 5.42025-05-16
Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hitachi Ops Center Analyzer: from 10.8.0-00 before 11.0.4-00; Hitachi Ops Center Analyzer: from 10.9.0-00 before 11.0.4-…
- CVE-2026-104380MEDIUMCVSS 5.3EG 5.32026-10-06
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET an…
- CVE-2026-67405MEDIUMCVSS 5.3EG 5.32026-09-23
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq_w…
- CVE-2025-61987MEDIUMCVSS 5.3EG 5.32025-12-12
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may b…
- CVE-2024-51775MEDIUMCVSS 5.3EG 5.32025-08-03
Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs. This issue affects Apach…
- CVE-2026-54565MEDIUMCVSS 4.7EG 4.72026-09-17
rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages, b…
- CVE-2023-2850MEDIUMCVSS 4.7EG 4.72023-07-25
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
- CVE-2026-18251MEDIUMCVSS 4.3EG 4.32026-09-14
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.
- CVE-2025-48068MEDIUMCVSS 4.3EG 4.32025-05-30
Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may have allowed limited source code exposure when the dev server was running with…
Map vulnerabilities like CWE-1385 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1385 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →