CVE-2026-42220: Websocket Index Ts Cwe 000 Cve 2026 42220

Direct connection to backend WebSocket in development mode using VITE_PROXY_TARGET. This skips the development server proxy and breaks middleware cookie injection, exposing unprotected initial handshakes.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-42220-websocket-index-ts-cwe-000-cve-2026-42220 --engine opengrep

Description

Direct connection to backend WebSocket in development mode using VITE_PROXY_TARGET. This skips the development server proxy and breaks middleware cookie injection, exposing unprotected initial handshakes.