Web Hack List

Collected research

Gitpod remote code execution 0-day vulnerability via WebSockets

Explains a Gitpod Cross-Site WebSocket Hijacking chain in which an attacker workspace shares the registrable site with the authenticated dashboard. SameSite cookies accompany the cross-origin WebSocket, exposing JSON-RPC methods that add an SSH key and take over workspaces and connected source control.

Record

Researcher
Elliot Ward
Published by
Snyk Labs
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Elliot Ward, first published at the original source. Preserved copies are kept so the citation survives its host.