CVE-2023-26114
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L/E:P
- EPSS probability
- 0.07%
- CWE
- CWE-1385
- Published
- 2023-03-23
- Last modified
- 2026-03-13
Affected products
- n/a code-server
Weakness type
Related vulnerabilities
- CVE-2025-24964 — Remote Code Execution when accessing a malicious website while Vitest API server is listening
- CVE-2024-48849 — Authentication and Authorization Issues
- CVE-2025-52882 — Claude Code IDE extensions allow websocket connections from arbitrary origins
- CVE-2023-30856 — eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution
- CVE-2023-0957 — An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSW
- CVE-2023-2848 — Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a miss
- CVE-2026-44211 — Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
- CVE-2026-85183 — Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS