npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm who visit their webpage and steal source code that is leaked by the WebSocket server.
{
"github_reviewed": true,
"severity": "MODERATE",
"github_reviewed_at": "2026-02-12T22:14:11Z",
"nvd_published_at": "2026-02-12T16:16:03Z",
"cwe_ids": [
"CWE-1385"
]
}