CVE-2026-85183

Source
https://cve.org/CVERecord?id=CVE-2026-85183
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85183.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85183
Published
2026-09-03T14:12:21.123Z
Modified
2026-09-05T03:48:29.589441176Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS
Details

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable modifications and action callbacks without CSRF protection.

Database specific
{
    "cwe_ids": [
        "CWE-1385"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85183.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/avaiga/taipy

Affected ranges

Type
GIT
Repo
https://github.com/avaiga/taipy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.1.1"
        }
    ]
}

Affected versions

4.*
4.0.0
4.0.0-common
4.0.0-core
4.0.0-gui
4.0.0-rest
4.0.0-templates
4.0.1
4.0.1-common
4.0.1-core
4.0.1-gui
4.0.1-rest
4.0.1-templates
4.0.2
4.0.2-common
4.0.2-core
4.0.2-gui
4.0.2-rest
4.0.2-templates
4.0.3
4.0.3-common
4.0.3-core
4.0.3-gui
4.0.3-rest
4.0.3-templates
4.1.0
4.1.0-common
4.1.0-core
4.1.0-gui
4.1.0-rest
4.1.0-templates
4.1.1
4.1.1-common
4.1.1-core
4.1.1-gui
4.1.1-rest
4.1.1-templates

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85183.json"