encore.dev is vulnerable to Cross-Site WebSocket Hijacking
43
Medium Risk
The local Encore developer dashboard exposes a JSON-RPC API over a WebSocket served by the CLI daemon on the developer's machine without validating the request Origin, so connections from any web origin are accepted. While a developer runs Encore locally, a website they visit can open a cross-origin WebSocket to the daemon and read information available through the dashboard. This does not reach Encore Cloud or production data, and modern browsers further limit the attack with a local-network permission prompt. The fix validates the WebSocket Origin and only accepts connections from loopback addresses.
You are affected if you are using a version that falls within the vulnerable range and you run the local Encore developer dashboard while browsing untrusted sites in the same browser profile.
encore.dev is vulnerable to Cross-Site WebSocket Hijacking in versions 0.0.1 - 1.57.5.
Upgrade the encore.dev library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant