Vendor
high
advisory
Unauthenticated Cross-Origin WebSocket Exploitation in Taipy
1 TTP 1 CVETaipy misconfigures its socket.io server with wildcard CORS and credentials enabled, permitting arbitrary domains to perform authenticated actions and state modifications via WebSockets without CSRF protections.
Taipy
web-application
cors
websocket
crsf
cve-2026-85183
1t
1c
high
advisory
Taipy 4.1.1 Path Traversal Vulnerability (CVE-2026-48544)
2 rules 1 TTP 1 CVETaipy 4.1.1 contains a path traversal vulnerability (CVE-2026-48544) in the ElementLibrary.get_resource() method that allows unauthenticated attackers to escape the intended module directory by exploiting an incomplete path containment check, enabling unauthorized file access outside the intended library directory.
Taipy 4.1.1
path-traversal
web-application
2r
1t
1c