Junglewise Threat Intelligence

CVE-2026-59804: web-infra-dev Midscene Bridge Server session hijack via CSWSH

CVE-2026-59804 · Severity: medium · CVSS 6.8 · Published 2026-07-08

Executive brief

Midscene Bridge Server, a tool used for web automation and testing, contains a security flaw that allows malicious websites to hijack active automation sessions. If a user visits a compromised website while the bridge server is running, the attacker can take control of the automation tools to steal data or inject unauthorized commands. This could lead to the exposure of sensitive browser data or the disruption of automated testing workflows.

Technical details

Midscene Bridge Server (running on port 3766) fails to validate the 'Origin' header during WebSocket handshakes and does not require an authentication token. This allows an unauthenticated remote attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack. By tricking a victim into visiting a malicious webpage, the attacker can establish a cross-origin Socket.IO connection to the local server. Once connected, the attacker can seize the single-client slot, intercept or inject automation commands, exfiltrate command payloads (such as screenshots), or shut down the server using the MIDSCENE_BRIDGE_SIGNAL_KILL parameter. The vulnerability is fixed in commit 86f4118 by implementing strict Origin-based access control.

Affected products

  • web-infra-dev Midscene Bridge Server <= 1.10.3

Timeline

  • 2026-07-05: disclosed: Issue reported on GitHub
  • 2026-07-07: patched: Fix merged in PR #2759
  • 2026-07-08: advisory: CVE published and VulnCheck advisory released

References