The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.
Volume of CVEs assigned to CWE-1385 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44211CRITICAL Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban | Jun 1, 2026 | 9.6 | 39 | NO | NO |
CVE-2026-10054HIGH In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) with | Jul 3, 2026 | 8.8 | 38 | NO | NO |
CVE-2024-48849CRITICAL Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= | Jan 29, 2025 | 9.4 | 37 | NO | YES |
CVE-2026-59950HIGH The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transp | Jul 15, 2026 | 8.1 | 35 | NO | NO |
CVE-2025-68930MEDIUM Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The | Feb 23, 2026 | 6.5 | 34 | NO | YES |
CVE-2026-57111HIGH Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows | Jul 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-34403HIGH Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin uncondition | Apr 20, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-35589CRITICAL nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/ser | Apr 14, 2026 | 9.3 | 31 | NO | NO |
CVE-2023-0957CRITICAL An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket co | Mar 3, 2023 | 9.6 | 30 | NO | NO |
CVE-2023-30856CRITICAL eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious we | Apr 28, 2023 | 10.0 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.