Cross-Domain Policy Vulnerability in Farion1231 CC-Switch ProxyServer
CVE-2026-6143
Key Information:
- Vendor
Farion1231
- Status
- Vendor
- CVE Published:
- 13 April 2026
Badges
What is CVE-2026-6143?
A security flaw has been identified in Farion1231's CC-Switch, specifically in the ProxyServer component found in the file src-tauri/src/proxy/server.rs. This vulnerability allows for a permissive cross-domain policy, potentially exposing sensitive functionalities to untrusted domains. The vulnerability can be exploited remotely, making it a significant risk for users and organizations. Furthermore, an exploit for this vulnerability has been publicly released, increasing the urgency for affected users to take immediate action to secure their systems.
Affected Version(s)
cc-switch 3.12.0
cc-switch 3.12.1
cc-switch 3.12.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
