CVE-2025-56647

MEDIUM

npm @farmfe/core <1.7.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm who visit their webpage and steal source code that is leaked by the WebSocket server.

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1385
Status published
Products (1)
farmfe/core 0 - 1.7.6npm
Published Feb 12, 2026
Tracked Since Feb 18, 2026