elm-watch is vulnerable to Cross-Site WebSocket Hijacking
21
Low Risk
In affected versions, a malicious website could connect to your local elm-watch WebSocket and perform various actions, including reading compiled Elm JavaScript and compilation errors, accessing your terminal's background and foreground colors, changing the compilation mode (debug, standard, optimize), repositioning elm-watch's browser UI, toggling the error overlay, and opening files in your editor. The last point is particularly critical because if you misconfigured your shell command for opening the editor, an attacker could execute malicious code on your computer.
You are affected if you are using a version that falls within the vulnerable range.
elm-watch is vulnerable to Cross-Site WebSocket Hijacking in versions 1.2.0 - 1.2.0 and 1.0.0 - 1.1.3.
Upgrade the elm-watch library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant