NPM · SEPTEMBER 2026 · EARLY WARNING

Critical Vulnerability in Taipy npm Package: CVE-2026-85183

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.3
Affected component
taipy (npm)
Affected versions
>= 4.1.1-templates, <= 4.1.1-templates or >= 4.1.1-rest, <= 4.1.1-rest or >= 4.1.1-gui, <= 4.1.1-gui or >= 4.1.1-core, <= 4.1.1-core or >= 4.1.1-common, <= 4.1.1-common or >= 4.1.1, <= 4.1.1 or >= 4.1.0-templates, <= 4.1.0-templates or >= 4.1.0-rest, <= 4.1.0-rest or >= 4.1.0-gui, <= 4.1.0-gui or >= 4.1.0-core, <= 4.1.0-core or >= 4.1.0-common, <= 4.1.0-common or >= 4.1.0, <= 4.1.0 or >= 4.0.3-templates, <= 4.0.3-templates or >= 4.0.3-rest, <= 4.0.3-rest or >= 4.0.3-gui, <= 4.0.3-gui or >= 4.0.3-core, <= 4.0.3-core or >= 4.0.3-common, <= 4.0.3-common or >= 4.0.3, <= 4.0.3 or >= 4.0.2-templates, <= 4.0.2-templates or >= 4.0.2-rest, <= 4.0.2-rest or >= 4.0.2-gui, <= 4.0.2-gui or >= 4.0.2-core, <= 4.0.2-core or >= 4.0.2-common, <= 4.0.2-common or >= 4.0.2, <= 4.0.2 or >= 4.0.1-templates, <= 4.0.1-templates or >= 4.0.1-rest, <= 4.0.1-rest or >= 4.0.1-gui, <= 4.0.1-gui or >= 4.0.1-core, <= 4.0.1-core or >= 4.0.1-common, <= 4.0.1-common or >= 4.0.1, <= 4.0.1 or >= 4.0.0-templates, <= 4.0.0-templates or >= 4.0.0-rest, <= 4.0.0-rest or >= 4.0.0-gui, <= 4.0.0-gui or >= 4.0.0-core, <= 4.0.0-core or >= 4.0.0-common, <= 4.0.0-common or >= 4.0.0, <= 4.0.0
Patched version
Not yet available
CVE-2026-85183

An early warning has been issued for a critical vulnerability in the Taipy npm package. This vulnerability allows any web page to establish credentialed WebSocket connections to victim applications.

What happened

The Taipy npm package reportedly configures its socket.io server with wildcard CORS origin and credential flag enabled. This configuration allows any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable modifications and action callbacks without CSRF protection. This vulnerability is currently under investigation.

The affected versions of Taipy are >= 4.1.1-templates, <= 4.1.1-templates or >= 4.1.1-rest, <= 4.1.1-rest or >= 4.1.1-gui, <= 4.1.1-gui or >= 4.1.1-core, <= 4.1.1-core or >= 4.1.1-common, <= 4.1.1-common or >= 4.1.1, <= 4.1.1 or >= 4.1.0-templates, <= 4.1.0-templates or >= 4.1.0-rest, <= 4.1.0-rest or >= 4.1.0-gui, <= 4.1.0-gui or >= 4.1.0-core, <= 4.1.0-core or >= 4.1.0-common, <= 4.1.0-common or >= 4.1.0, <= 4.1.0 or >= 4.0.3-templates, <= 4.0.3-templates or >= 4.0.3-rest, <= 4.0.3-rest or >= 4.0.3-gui, <= 4.0.3-gui or >= 4.0.3-core, <= 4.0.3-core or >= 4.0.3-common, <= 4.0.3-common or >= 4.0.3, <= 4.0.3 or >= 4.0.2-templates, <= 4.0.2-templates or >= 4.0.2-rest, <= 4.0.2-rest or >= 4.0.2-gui, <= 4.0.2-gui or >= 4.0.2-core, <= 4.0.2-core or >= 4.0.2-common, <= 4.0.2-common or >= 4.0.2, <= 4.0.2 or >= 4.0.1-templates, <= 4.0.1-templates or >= 4.0.1-rest, <= 4.0.1-rest or >= 4.0.1-gui, <= 4.0.1-gui or >= 4.0.1-core, <= 4.0.1-core or >= 4.0.1-common, <= 4.0.1-common or >= 4.0.1, <= 4.0.1 or >= 4.0.0-templates, <= 4.0.0-templates or >= 4.0.0-rest, <= 4.0.0-rest or >= 4.0.0-gui, <= 4.0.0-gui or >= 4.0.0-core, <= 4.0.0-core or >= 4.0.0-common, <= 4.0.0-common or >= 4.0.0, <= 4.0.0. Users of these versions should take immediate action to assess their exposure.

To assess your exposure, check if your application uses any of the affected versions of Taipy. If so, review your application's CORS settings and consider upgrading to a patched version if available.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If taipy is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if your application uses any version of Taipy >= 4.1.1-templates, <= 4.1.1-templates or >= 4.1.1-rest, <= 4.1.1-rest or >= 4.1.1-gui, <= 4.1.1-gui or >= 4.1.1-core, <= 4.1.1-core or >= 4.1.1-common, <= 4.1.1-common or >= 4.1.1, <= 4.1.1 or >= 4.1.0-templates, <= 4.1.0-templates or >= 4.1.0-rest, <= 4.1.0-rest or >= 4.1.0-gui, <= 4.1.0-gui or >= 4.1.0-core, <= 4.1.0-core or >= 4.1.0-common, <= 4.1.0-common or >= 4.1.0, <= 4.1.0 or >= 4.0.3-templates, <= 4.0.3-templates or >= 4.0.3-rest, <= 4.0.3-rest or >= 4.0.3-gui, <= 4.0.3-gui or >= 4.0.3-core, <= 4.0.3-core or >= 4.0.3-common, <= 4.0.3-common or >= 4.0.3, <= 4.0.3 or >= 4.0.2-templates, <= 4.0.2-templates or >= 4.0.2-rest, <= 4.0.2-rest or >= 4.0.2-gui, <= 4.0.2-gui or >= 4.0.2-core, <= 4.0.2-core or >= 4.0.2-common, <= 4.0.2-common or >= 4.0.2, <= 4.0.2 or >= 4.0.1-templates, <= 4.0.1-templates or >= 4.0.1-rest, <= 4.0.1-rest or >= 4.0.1-gui, <= 4.0.1-gui or >= 4.0.1-core, <= 4.0.1-core or >= 4.0.1-common, <= 4.0.1-common or >= 4.0.1, <= 4.0.1 or >= 4.0.0-templates, <= 4.0.0-templates or >= 4.0.0-rest, <= 4.0.0-rest or >= 4.0.0-gui, <= 4.0.0-gui or >= 4.0.0-core, <= 4.0.0-core or >= 4.0.0-common, <= 4.0.0-common or >= 4.0.0, <= 4.0.0.

What should I do right now?

Upgrade to the latest version of Taipy that patches this vulnerability and review your application's CORS settings.

Is there an official fix available?

No official fix has been published yet. Monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats