code-server@4.2.0-5014-d680eef5ea388929ee958eafc290f287d777a18d vulnerabilities

Run VS Code on a remote server.

  • latest version

    4.100.2

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    14 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the code-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Server-side Request Forgery (SSRF)

    code-server is an application that allows running VS Code on a remote server.

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the proxy subpath. An attacker can gain unauthorized access to session tokens by crafting a malicious URL that manipulates the proxy functionality to redirect to an arbitrary domain. This occurs due to improper validation of an expected local proxy port for requests, allowing proxying to an arbitrary domain.

    Note: This vulnerability requires the built-in proxy in the Code-Server to be enabled

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade code-server to version 4.99.4 or higher.

    <4.99.4
    • H
    Missing Origin Validation in WebSockets

    code-server is an application that allows running VS Code on a remote server.

    Affected versions of this package are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

    How to fix Missing Origin Validation in WebSockets?

    Upgrade code-server to version 4.10.1 or higher.

    <4.10.1