Executive brief
Taipy is a framework for building production web applications with data and AI algorithms. Due to improper Cross-Origin Resource Sharing (CORS) configuration on its socket.io server, an attacker can open malicious web pages that establish credentialed WebSocket connections to Taipy applications running on victim machines. This allows attackers to modify application state, invoke backend functions, and potentially compromise sensitive data or application integrity without the user's knowledge.
Technical details
Taipy's socket.io server is configured with a wildcard CORS origin (*) and the credential flag enabled, a misconfiguration that violates browser same-origin policy protections. This allows any arbitrary web page to establish authenticated WebSocket connections to Taipy applications. An attacker can craft a malicious website that, when visited by a user running a Taipy application, silently connects to the local or remote Taipy instance and invokes state variable modifications and action callbacks. The vulnerability requires no CSRF tokens or additional authentication, as the browser automatically includes credentials in cross-origin socket.io requests. No authentication bypass is required if the Taipy application itself lacks proper access controls.
Affected products
- Avaiga Taipy 4.1.1 and prior
Timeline
- 2026-09-03: disclosed