CVE-2023-30856
eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control websocket, and send arbitrary commands to the shell. The project has been archived since 2021, and as of time of publication there are no plans to patch this issue and release a new version. Some workarounds are available, including shutting down eDEX-UI when browsing the web and ensuring the eDEX terminal runs with lowest possible privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
- EPSS probability
- 0.17%
- CWE
- CWE-1385, CWE-346
- Published
- 2023-04-28
- Last modified
- 2026-03-13
Affected products
- GitSquared edex-ui
Weakness type
Related vulnerabilities
- CVE-2025-24964 — Remote Code Execution when accessing a malicious website while Vitest API server is listening
- CVE-2024-48849 — Authentication and Authorization Issues
- CVE-2025-52882 — Claude Code IDE extensions allow websocket connections from arbitrary origins
- CVE-2023-0957 — An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSW
- CVE-2023-26114 — Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.
- CVE-2023-2848 — Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a miss
- CVE-2026-44211 — Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
- CVE-2026-85183 — Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS