CRITICAL
9.3 CVE-2026-85183 Published 3 Sept 2026
Taipy Web App Socket.IO CORS Misconfiguration
Worried this affects one of your servers?
Taipy, a web application framework, misconfigures its Socket.IO server with wildcard CORS origin and credential flag enabled.
This allows any web page to establish credentialed WebSocket connections to victim applications, bypassing CSRF protection.
Impact: Attackers can invoke state variable modifications and action callbacks without user interaction.
Reference: CVE-2026-85183 on NVD
← Back to Security News