headroom-ai is vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
88
High Risk
The headroom-ai proxy exposes a WebSocket server at /v1/responses that does not validate the Origin header during the handshake. Web content loaded in the browser of a user running the local proxy can open a cross-origin WebSocket to it, and the server accepts the connection and automatically injects the configured OPENAI_API_KEY as the upstream credential. Untrusted pages can therefore issue authenticated LLM API requests through the proxy without supplying any credentials, enabling data exfiltration, quota abuse, and tool-driven actions. The fix validates the request Origin on the WebSocket handshake and rejects cross-origin connections.
You are affected if you are using a version that falls within the vulnerable range and you run the Headroom proxy so its /v1/responses WebSocket endpoint is reachable from a web browser.
headroom-ai is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) in versions 0.5.16 - 0.27.0.
Upgrade the headroom-ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.