Skip to content

[GHSA-p773-8mf4-rjm5] @farmfe/core is Missing Origin Validation in WebSocket#6931

Open
cai0duque wants to merge 1 commit intocai0duque/advisory-improvement-6931from
cai0duque-GHSA-p773-8mf4-rjm5
Open

[GHSA-p773-8mf4-rjm5] @farmfe/core is Missing Origin Validation in WebSocket#6931
cai0duque wants to merge 1 commit intocai0duque/advisory-improvement-6931from
cai0duque-GHSA-p773-8mf4-rjm5

Conversation

@cai0duque
Copy link

Updates

  • CVSS v3
  • CVSS v4
  • Description
  • Severity

Comments
Updated severity metrics to CVSS 4.0 to more accurately reflect the "Passive" User Interaction required for Cross-Site WebSocket Hijacking (CSWSH). Refined the description to explicitly use the industry-standard term CSWSH and clarify the attack scenario.

Copilot AI review requested due to automatic review settings February 17, 2026 09:17
@github-actions github-actions bot changed the base branch from main to cai0duque/advisory-improvement-6931 February 17, 2026 09:18
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates a security advisory (GHSA-p773-8mf4-rjm5) for the @farmfe/core npm package to improve its accuracy and clarity. The advisory addresses a Cross-Site WebSocket Hijacking (CSWSH) vulnerability due to missing origin validation in the WebSocket server used for hot module reloading.

Changes:

  • Upgraded CVSS scoring from v3.1 to v4.0, reflecting the "Passive" user interaction required for the attack
  • Increased severity from MODERATE to HIGH based on the updated CVSS v4.0 metrics
  • Enhanced the vulnerability description to use industry-standard CSWSH terminology and provide clearer attack scenario details

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant