{"id":"GHSA-hqwm-7x7x-8379","summary":"DevSpace UI Server WebSocket CheckOrigin does not validate source","details":"### Description\n\nDevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the same time uses a browser to access the internet, a malicious website they visit can use their browser to establish a cross-origin WebSocket connection to `ws://127.0.0.1:8090`. This allows an attacker to access: \n* `/api/logs` to stream real-time pod logs\n* `/api/enter` to open an interactive shell inside the running pod\n* `/api/command` to execute pre-defined pipeline commands\n\n### Patches\n\nVersions 6.3.21 and above are patched.\n\n### Resources\n\n[gorilla/websocket CheckOrigin documentation](https://pkg.go.dev/github.com/gorilla/websocket#hdr-Origin_Considerations)\n\n### Installation Options\n\nDevspace is no longer publishing to NPM or Yarn, please continue to use our [other installation methods](https://www.devspace.sh/docs/getting-started/installation) to get updates in the future, including this patch.\n\n### Credit\n\nDevSpace thanks @b0b0haha for finding and reporting this vulnerability.","aliases":["CVE-2026-42283","GO-2026-5433"],"modified":"2026-06-25T23:11:48.629535134Z","published":"2026-05-06T17:05:57Z","database_specific":{"nvd_published_at":"2026-05-14T16:16:21Z","cwe_ids":["CWE-200","CWE-306"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-06T17:05:57Z"},"references":[{"type":"WEB","url":"https://github.com/devspace-sh/devspace/security/advisories/GHSA-hqwm-7x7x-8379"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42283"},{"type":"PACKAGE","url":"https://github.com/devspace-sh/devspace"}],"affected":[{"package":{"name":"github.com/loft-sh/devspace","ecosystem":"Go","purl":"pkg:golang/github.com/loft-sh/devspace"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.3.20"},{"fixed":"6.3.21"}]}],"versions":["6.3.20"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-hqwm-7x7x-8379/GHSA-hqwm-7x7x-8379.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}