code-server@3.3.0-rc.5 vulnerabilities

Run VS Code on a remote server.

Direct Vulnerabilities

Known vulnerabilities in the code-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Missing Origin Validation in WebSockets

code-server is an application that allows running VS Code on a remote server.

Affected versions of this package are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

How to fix Missing Origin Validation in WebSockets?

Upgrade code-server to version 4.10.1 or higher.

<4.10.1
  • M
Cross-site Scripting (XSS)

code-server is an application that allows running VS Code on a remote server.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via a specially crafted URL which executes JavaScript code when clicked.

How to fix Cross-site Scripting (XSS)?

Upgrade code-server to version 4.0.1 or higher.

<4.0.1
  • H
Regular Expression Denial of Service (ReDoS)

code-server is an application that allows running VS Code on a remote server.

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via a regular expression in the pattern variable in src/node/util.ts.

How to fix Regular Expression Denial of Service (ReDoS)?

Upgrade code-server to version 3.12.0 or higher.

<3.12.0