Cross-Origin Request Vulnerability in Waku Minimal React Framework
CVE-2026-49455
6.5MEDIUM
What is CVE-2026-49455?
The Waku Minimal React Framework contains a cross-origin request vulnerability due to the improper handling of the Origin header within its server action dispatcher. Versions prior to 1.0.0-beta.1 lack validation for the request’s Origin or Sec-Fetch-Site header, allowing malicious actors to exploit this flaw. An attacker can craft a malicious request that forces a victim's browser to make authenticated POST requests to certain server action endpoints, potentially compromising user data and session integrity. This vulnerability has been addressed in version 1.0.0-beta.1.
Affected Version(s)
waku < 1.0.0-beta.1
