WebSocket Security Flaw in Browserify-HMR Affects Developers
CVE-2018-14730
7.5HIGH
Key Information:
- Vendor
- CVE Published:
- 21 September 2018
What is CVE-2018-14730?
A security issue has been identified in Browserify-HMR where the WebSocket server fails to validate the origin of incoming requests. This vulnerability allows attackers to intercept Hot Module Replacement (HMR) messages, enabling them to access and potentially steal developer code through unauthorized connections. Specifically, by establishing a connection to ws://127.0.0.1:3123/ from any origin, malicious actors can exploit this oversight, posing a significant risk to developers who rely on HMR for efficient code updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
