{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ataipytaipy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:taipy:taipy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-85183"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Taipy"],"_cs_severities":["high"],"_cs_tags":["web-application","cors","websocket","crsf","cve-2026-85183"],"_cs_type":"advisory","_cs_vendors":["Taipy"],"content_html":"\u003cp\u003eTaipy versions configured with default socket.io settings are vulnerable to a critical cross-origin configuration flaw (CVE-2026-85183). The application enables both a wildcard Cross-Origin Resource Sharing (CORS) origin policy and the 'credentials' flag within its WebSocket implementation. This combination allows an attacker to host a malicious webpage that forces a victim's browser to establish a credentialed WebSocket connection to the Taipy server. Because the server trusts the origin and processes credentials, the attacker can execute unauthorized state variable modifications and trigger server-side action callbacks. This vulnerability effectively bypasses traditional CSRF protections for the WebSocket channel, potentially leading to full unauthorized control over the Taipy application instance. Defenders must note that this vulnerability resides in the application's configuration of its communication layer, which persists as long as the default socket.io policy remains in place.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to perform unauthorized actions on behalf of authenticated users, including the modification of internal application state and the execution of server-side logic (action callbacks). This bypass of CSRF protection poses a significant risk to application integrity and data security, particularly in multi-user Taipy deployments where administrative or sensitive user actions are performed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize an audit of Taipy WebSocket configurations to ensure the 'Access-Control-Allow-Origin' header is restricted to trusted, specific domains rather than a wildcard ('*').\u003c/li\u003e\n\u003cli\u003eDisable the transmission of credentials (cookies/authorization headers) for cross-origin WebSocket connections if cross-domain access is required.\u003c/li\u003e\n\u003cli\u003eImplement strict origin validation logic within the socket.io 'connection' middleware to drop any incoming requests that do not originate from expected application domains.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for WebSocket connection attempts originating from unknown or unexpected HTTP 'Origin' headers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T15:21:39Z","date_published":"2026-09-03T15:21:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-taipy-cors-misconfig/","summary":"Taipy misconfigures its socket.io server with wildcard CORS and credentials enabled, permitting arbitrary domains to perform authenticated actions and state modifications via WebSockets without CSRF protections.","title":"Unauthenticated Cross-Origin WebSocket Exploitation in Taipy","url":"https://feed.craftedsignal.io/briefs/2026-09-taipy-cors-misconfig/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:taipy:taipy:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}