Critical Vulnerability in Taipy npm Package: CVE-2026-85183
- Severity
- CRITICAL
- CVSS
- 9.3
- Affected component
- taipy (npm)
- Affected versions
- >= 4.1.1-templates, <= 4.1.1-templates or >= 4.1.1-rest, <= 4.1.1-rest or >= 4.1.1-gui, <= 4.1.1-gui or >= 4.1.1-core, <= 4.1.1-core or >= 4.1.1-common, <= 4.1.1-common or >= 4.1.1, <= 4.1.1 or >= 4.1.0-templates, <= 4.1.0-templates or >= 4.1.0-rest, <= 4.1.0-rest or >= 4.1.0-gui, <= 4.1.0-gui or >= 4.1.0-core, <= 4.1.0-core or >= 4.1.0-common, <= 4.1.0-common or >= 4.1.0, <= 4.1.0 or >= 4.0.3-templates, <= 4.0.3-templates or >= 4.0.3-rest, <= 4.0.3-rest or >= 4.0.3-gui, <= 4.0.3-gui or >= 4.0.3-core, <= 4.0.3-core or >= 4.0.3-common, <= 4.0.3-common or >= 4.0.3, <= 4.0.3 or >= 4.0.2-templates, <= 4.0.2-templates or >= 4.0.2-rest, <= 4.0.2-rest or >= 4.0.2-gui, <= 4.0.2-gui or >= 4.0.2-core, <= 4.0.2-core or >= 4.0.2-common, <= 4.0.2-common or >= 4.0.2, <= 4.0.2 or >= 4.0.1-templates, <= 4.0.1-templates or >= 4.0.1-rest, <= 4.0.1-rest or >= 4.0.1-gui, <= 4.0.1-gui or >= 4.0.1-core, <= 4.0.1-core or >= 4.0.1-common, <= 4.0.1-common or >= 4.0.1, <= 4.0.1 or >= 4.0.0-templates, <= 4.0.0-templates or >= 4.0.0-rest, <= 4.0.0-rest or >= 4.0.0-gui, <= 4.0.0-gui or >= 4.0.0-core, <= 4.0.0-core or >= 4.0.0-common, <= 4.0.0-common or >= 4.0.0, <= 4.0.0
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the Taipy npm package. This vulnerability allows any web page to establish credentialed WebSocket connections to victim applications.
What happened
The Taipy npm package reportedly configures its socket.io server with wildcard CORS origin and credential flag enabled. This configuration allows any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable modifications and action callbacks without CSRF protection. This vulnerability is currently under investigation.
The affected versions of Taipy are >= 4.1.1-templates, <= 4.1.1-templates or >= 4.1.1-rest, <= 4.1.1-rest or >= 4.1.1-gui, <= 4.1.1-gui or >= 4.1.1-core, <= 4.1.1-core or >= 4.1.1-common, <= 4.1.1-common or >= 4.1.1, <= 4.1.1 or >= 4.1.0-templates, <= 4.1.0-templates or >= 4.1.0-rest, <= 4.1.0-rest or >= 4.1.0-gui, <= 4.1.0-gui or >= 4.1.0-core, <= 4.1.0-core or >= 4.1.0-common, <= 4.1.0-common or >= 4.1.0, <= 4.1.0 or >= 4.0.3-templates, <= 4.0.3-templates or >= 4.0.3-rest, <= 4.0.3-rest or >= 4.0.3-gui, <= 4.0.3-gui or >= 4.0.3-core, <= 4.0.3-core or >= 4.0.3-common, <= 4.0.3-common or >= 4.0.3, <= 4.0.3 or >= 4.0.2-templates, <= 4.0.2-templates or >= 4.0.2-rest, <= 4.0.2-rest or >= 4.0.2-gui, <= 4.0.2-gui or >= 4.0.2-core, <= 4.0.2-core or >= 4.0.2-common, <= 4.0.2-common or >= 4.0.2, <= 4.0.2 or >= 4.0.1-templates, <= 4.0.1-templates or >= 4.0.1-rest, <= 4.0.1-rest or >= 4.0.1-gui, <= 4.0.1-gui or >= 4.0.1-core, <= 4.0.1-core or >= 4.0.1-common, <= 4.0.1-common or >= 4.0.1, <= 4.0.1 or >= 4.0.0-templates, <= 4.0.0-templates or >= 4.0.0-rest, <= 4.0.0-rest or >= 4.0.0-gui, <= 4.0.0-gui or >= 4.0.0-core, <= 4.0.0-core or >= 4.0.0-common, <= 4.0.0-common or >= 4.0.0, <= 4.0.0. Users of these versions should take immediate action to assess their exposure.
To assess your exposure, check if your application uses any of the affected versions of Taipy. If so, review your application's CORS settings and consider upgrading to a patched version if available.
What to do about it
- Upgrade to the latest version of Taipy that patches this vulnerability.
- Review your application's CORS settings to ensure they are secure.
- Monitor the primary sources for updates on this vulnerability.
- Consider implementing additional security measures to protect against potential attacks.
How 0Day would have caught this
taipy is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if your application uses any version of Taipy >= 4.1.1-templates, <= 4.1.1-templates or >= 4.1.1-rest, <= 4.1.1-rest or >= 4.1.1-gui, <= 4.1.1-gui or >= 4.1.1-core, <= 4.1.1-core or >= 4.1.1-common, <= 4.1.1-common or >= 4.1.1, <= 4.1.1 or >= 4.1.0-templates, <= 4.1.0-templates or >= 4.1.0-rest, <= 4.1.0-rest or >= 4.1.0-gui, <= 4.1.0-gui or >= 4.1.0-core, <= 4.1.0-core or >= 4.1.0-common, <= 4.1.0-common or >= 4.1.0, <= 4.1.0 or >= 4.0.3-templates, <= 4.0.3-templates or >= 4.0.3-rest, <= 4.0.3-rest or >= 4.0.3-gui, <= 4.0.3-gui or >= 4.0.3-core, <= 4.0.3-core or >= 4.0.3-common, <= 4.0.3-common or >= 4.0.3, <= 4.0.3 or >= 4.0.2-templates, <= 4.0.2-templates or >= 4.0.2-rest, <= 4.0.2-rest or >= 4.0.2-gui, <= 4.0.2-gui or >= 4.0.2-core, <= 4.0.2-core or >= 4.0.2-common, <= 4.0.2-common or >= 4.0.2, <= 4.0.2 or >= 4.0.1-templates, <= 4.0.1-templates or >= 4.0.1-rest, <= 4.0.1-rest or >= 4.0.1-gui, <= 4.0.1-gui or >= 4.0.1-core, <= 4.0.1-core or >= 4.0.1-common, <= 4.0.1-common or >= 4.0.1, <= 4.0.1 or >= 4.0.0-templates, <= 4.0.0-templates or >= 4.0.0-rest, <= 4.0.0-rest or >= 4.0.0-gui, <= 4.0.0-gui or >= 4.0.0-core, <= 4.0.0-core or >= 4.0.0-common, <= 4.0.0-common or >= 4.0.0, <= 4.0.0.
What should I do right now?
Upgrade to the latest version of Taipy that patches this vulnerability and review your application's CORS settings.
Is there an official fix available?
No official fix has been published yet. Monitor the primary sources for updates.