# CVE-2023-0957

## Summary

- **CVE ID:** CVE-2023-0957
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L)
- **CWE:** CWE-1385
- **Published:** Mar 3, 2023
- **Last Modified:** Mar 13, 2026

## Description

An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace.

## Affected Products

- Gitpod — Gitpod (0)

## References

- [CNA](https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=default&orgId=71ccd717-aa2d-4a1e-942e-c768d37e9e0c&tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d)
- [CNA](https://github.com/gitpod-io/gitpod/releases/tag/release-2022.11.2)
- [CNA](https://github.com/gitpod-io/gitpod/pull/16378)
- [CNA](https://github.com/gitpod-io/gitpod/pull/16405)
- [CNA](https://github.com/gitpod-io/gitpod/commit/12956988eec0031f42ffdfa3bdc3359f65628f9f)
- [CNA](https://github.com/gitpod-io/gitpod/commit/673ab6856fa04c13b7b1f2a968e4d090f1d94e4f)
- [CNA](https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 49.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._