CPE
Taipy misconfigures its socket.io server with wildcard CORS and credentials enabled, permitting arbitrary domains to perform authenticated actions and state modifications via WebSockets without CSRF protections.