CVE-2023-30856: high-severity vulnerability in GitSquared edex-ui
eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
eDEX-UI, a terminal emulator, has a flaw that lets malicious websites connect to its internal control system and run harmful commands on your computer while you browse the web. This is serious because it can give attackers direct access to your system.
Cross-site WebSocket hijacking vulnerability in eDEX-UI versions ≤2.2.8 allows unauthenticated remote command execution via a malicious website that establishes a connection to the unprotected internal WebSocket endpoint. The vulnerability requires a victim to visit the attacker's site while eDEX-UI is running, exploiting insufficient CORS/origin validation on the WebSocket handler.