CVE-2023-26114

HIGH

code-server <4.10.1 - Info Disclosure

Title source: llm

Description

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

Scores

CVSS v3 8.2
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L

Classification

CWE
CWE-346 CWE-1385
Status published

Affected Products (2)

coder/code-server < 4.10.1
npm/code-server < 4.10.1npm

Timeline

Published Mar 23, 2023
Tracked Since Feb 18, 2026