{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aheadroom_aiheadroom/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:headroom_ai:headroom:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-71416"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["headroom (\u003c 0.35.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Headroom AI"],"content_html":"\u003cp\u003eThe Headroom WebSocket server (pip package \u003ccode\u003eheadroom-ai\u003c/code\u003e version \u0026lt; 0.35.0) is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) due to a failure to validate the \u003ccode\u003eOrigin\u003c/code\u003e header during the initial WebSocket handshake. By default, the Headroom proxy is configured to facilitate LLM interactions and will automatically inject the \u003ccode\u003eOPENAI_API_KEY\u003c/code\u003e environment variable into the \u003ccode\u003eAuthorization\u003c/code\u003e header of outgoing requests if the client fails to provide one.\u003c/p\u003e\n\u003cp\u003eAn attacker can host a malicious webpage that, when visited by a user or headless browser with internal network access to the Headroom proxy, initiates an unauthorized WebSocket connection to \u003ccode\u003ews://\u0026lt;headroom_host\u0026gt;:8787/v1/responses\u003c/code\u003e. Once established, the attacker can submit arbitrary prompts or tool instructions - such as local shell execution requests - which the proxy will authenticate using the environment-stored API key. This flaw enables unauthenticated remote command execution (RCE) via the proxy's tool-calling capabilities and can result in significant financial loss through quota exhaustion.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an accessible instance of a Headroom proxy on an internal network.\u003c/li\u003e\n\u003cli\u003eAttacker hosts a malicious webpage containing a WebSocket client targeting the Headroom proxy at \u003ccode\u003e/v1/responses\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eA user within the network visits the malicious webpage via a web browser or a headless browser (e.g., lightpanda).\u003c/li\u003e\n\u003cli\u003eThe browser initiates a WebSocket upgrade request to the Headroom proxy; the proxy fails to validate the \u003ccode\u003eOrigin\u003c/code\u003e header of the request.\u003c/li\u003e\n\u003cli\u003eThe proxy accepts the malicious connection and creates a WebSocket bridge.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a \u003ccode\u003eresponse.create\u003c/code\u003e JSON payload over the socket, including a tool execution command (e.g., \u003ccode\u003etype: \u0026quot;shell\u0026quot;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eHeadroom observes the missing \u003ccode\u003eAuthorization\u003c/code\u003e header, retrieves the \u003ccode\u003eOPENAI_API_KEY\u003c/code\u003e from the environment, and injects it into the upstream request to OpenAI.\u003c/li\u003e\n\u003cli\u003eThe upstream OpenAI API executes the requested tool or prompt, returning the results or triggering RCE in the local environment if shell tools are enabled.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized LLM model usage, potentially leading to the leakage of proprietary information or sensitive context. More critically, if shell tools or other system-level integrations are enabled in the Headroom configuration, the attacker can achieve remote command execution on the host machine. Furthermore, organizations face the risk of service disruption and financial impact due to the unauthorized consumption of OpenAI API quotas.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003eheadroom-ai\u003c/code\u003e to version 0.35.0 or later immediately to incorporate Origin header validation.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control to restrict access to the Headroom proxy endpoint (\u003ccode\u003e/v1/responses\u003c/code\u003e) to trusted internal segments only.\u003c/li\u003e\n\u003cli\u003eAvoid storing \u003ccode\u003eOPENAI_API_KEY\u003c/code\u003e as a persistent environment variable on servers where the proxy is accessible by untrusted clients; utilize restricted IAM roles or transient credential stores if possible.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected WebSocket connections to the Headroom proxy port (default 8787) originating from client web browsers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T04:50:52Z","date_published":"2026-10-03T04:50:52Z","id":"https://feed.craftedsignal.io/briefs/2026-10-headroom-cswsh/","summary":"The Headroom WebSocket server lacks Origin header validation, enabling Cross-Site WebSocket Hijacking that allows unauthorized parties to perform LLM requests via an injected OpenAI API key.","title":"Cross-Site WebSocket Hijacking in Headroom","url":"https://feed.craftedsignal.io/briefs/2026-10-headroom-cswsh/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:headroom_ai:headroom:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}