Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1577

NIXPKGS-2026-1577
published 1 month, 1 week ago
Permalink CVE-2026-42283
7.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 month, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.azure-mgmt-devspaces
    • python313Packages.azure-mgmt-devspaces
    • python314Packages.azure-mgmt-devspaces
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
DevSpace UI Server WebSocket CheckOrigin does not validate source

DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the same time uses a browser to access the internet, a malicious website they visit can use their browser to establish a cross-origin WebSocket connection to ws://127.0.0.1:8090. This vulnerability is fixed in 6.3.21.

Affected products

devspace
  • ==< 6.3.21

Matching in nixpkgs

pkgs.devspace

Open-source developer tool for Kubernetes that lets you develop and deploy cloud-native software faster

Ignored packages (3)

Package maintainers