Gitpod provides a cloud-based development environment platform accessed primarily through web browsers, and its vulnerability footprint concentrates in its core platform product around web-tier input handling and trust-validation defects. The recurring weakness classes—cross-site scripting, open redirects, and WebSocket origin-validation errors—reflect the challenges of securing user-facing web applications that bridge local development tooling with remote execution and authentication contexts. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitpod over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0957CRITICAL An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket co | Mar 3, 2023 | 9.6 | 30 | NO | NO |
CVE-2023-32766MEDIUM Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:). | Jun 5, 2023 | 6.1 | 20 | NO | NO |
CVE-2021-35206MEDIUM Gitpod before 0.6.0 allows unvalidated redirects. | Jun 22, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitpod.
Media articles that mention a CVE ID that affects a product developed by Gitpod — matched by CVE ID, not by vendor name.