Description
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm who visit their webpage and steal source code that is leaked by the WebSocket server.
Recommendation
Update the @farmfe/core package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.7.6
- Patched version(s): 1.7.6
References
Could your website be exposed too?
SmartScanner can check your website for @farmfe/core is Missing Origin Validation in WebSocket and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Missing Origin Validation in parcel-bundler - parcel-bundler - CVE-2018-14731
- locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext Editor - CVE-2026-41886
- Missing Origin Validation in browserify-hmr - CVE-2018-14730
- Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - @apollo/sandbox - CVE-2025-59845


