Collected research
Gitpod remote code execution 0-day vulnerability via WebSockets
Explains a Gitpod Cross-Site WebSocket Hijacking chain in which an attacker workspace shares the registrable site with the authenticated dashboard. SameSite cookies accompany the cross-origin WebSocket, exposing JSON-RPC methods that add an SSH key and take over workspaces and connected source control.
Record
- Researcher
- Elliot Ward
- Published by
- Snyk Labs
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Elliot Ward, first published at the original source. Preserved copies are kept so the citation survives its host.