{"id":"CVE-2023-26114","details":"Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.","aliases":["GHSA-frjg-g767-7363"],"modified":"2026-08-27T03:57:00.279739936Z","published":"2023-03-23T05:00:01.220Z","related":["CGA-mj3m-xrm9-qv7g"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26114.json","cna_assigner":"snyk","cwe_ids":["CWE-1385"]},"references":[{"type":"WEB","url":"https://github.com/coder/code-server/releases/tag/v4.10.1"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-CODESERVER-3368148"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26114.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26114"},{"type":"FIX","url":"https://github.com/coder/code-server/commit/d477972c68fc8c8e8d610aa7287db87ba90e55c7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/coder/code-server","events":[{"introduced":"0"},{"fixed":"d477972c68fc8c8e8d610aa7287db87ba90e55c7"}],"database_specific":{"cpe":"cpe:2.3:a:coder:code-server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.10.1"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["v4.10.0-rc.2","v4.10.0","v4.10.0-rc.1","v4.9.0-rc.0","v4.8.1","v4.8.1-rc.1","v4.8.0","v4.7.1","v4.5.0","v4.1.0","v3.12.0","v3.9.1","3.4.1","3.4.0","v3.3.0","3.2.0","3.1.1","3.1.0","3.0.2","3.0.1","3.0.0","2.1698","2.1692-vsc1.39.2","2.1688-vsc1.39.2","2.1665-vsc1.39.2","2.1662-vsc1.39.2","2.1655-vsc1.39.2","2.1650-vsc1.39.2","2.1638-vsc1.39.2","2.1637-vsc1.39.2","2.1523-vsc1.38.1","2.1485-vsc1.38.1","2.1478-vsc1.38.1","2.1472-vsc1.38.1","1.1119-vsc1.33.1","1.1156-vsc1.33.1","1.1140-vsc1.33.1","1.1106-vsc1.33.1","1.1099-vsc1.33.1","1.939-vsc1.33.1","1.903-vsc1.33.1","1.868-vsc1.33.1","1.854-vsc1.33.1","1.792-vsc1.33.1","1.790-vsc1.33.1","1.696-vsc1.33.0","1.691-vsc1.33.0","1.604-vsc1.32.0","1.408-vsc1.32.0","1.32.0-310","1.32.0-282","1.32.0-275","1.32.0-245","1.31.1-100","1.31.0-20","1.31.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26114.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L/E:P"}]}