CVE-2026-59804: Missing Origin Validation in WebSockets in web-infra-dev midscene
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active bridge sessions by opening a cross-origin WebSocket connection to the local Socket.IO server, which performs no Origin header validation and requires no authentication token. Attackers can connect from any web page visited by the victim to seize the single-client slot, intercept and inject automation commands, exfiltrate command-payload data, or unconditionally terminate the server by supplying the MIDSCENE_BRIDGE_SIGNAL_KILL query parameter.
AI Analysis
Technical Summary
CVE-2026-59804 describes a missing authentication and CORS misconfiguration vulnerability in Midscene Bridge Server through version 1.10.3. The local Socket.IO server accepts WebSocket connections without validating the Origin header and does not require authentication tokens. This flaw enables unauthenticated attackers to connect from any web page visited by the victim, hijack the single-client WebSocket slot, intercept and inject automation commands, exfiltrate command-payload data, or terminate the server by sending a query parameter MIDSCENE_BRIDGE_SIGNAL_KILL. The vulnerability is fixed in a later commit (86f4118), but no official patch or advisory details are provided in this data.
Potential Impact
An attacker can remotely hijack active bridge sessions without authentication by exploiting the lack of Origin validation in WebSocket connections. This can result in unauthorized command injection, data exfiltration, and denial of service by forcibly terminating the server. The vulnerability affects confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability is fixed in commit 86f4118, so applying the fix from this commit or upgrading beyond version 1.10.3 is recommended once official patches or releases are available. Until then, restricting WebSocket access to trusted origins or network segments may reduce exposure.
CVE-2026-59804: Missing Origin Validation in WebSockets in web-infra-dev midscene
Description
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active bridge sessions by opening a cross-origin WebSocket connection to the local Socket.IO server, which performs no Origin header validation and requires no authentication token. Attackers can connect from any web page visited by the victim to seize the single-client slot, intercept and inject automation commands, exfiltrate command-payload data, or unconditionally terminate the server by supplying the MIDSCENE_BRIDGE_SIGNAL_KILL query parameter.
CVSS v4.0
Score 7.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59804 describes a missing authentication and CORS misconfiguration vulnerability in Midscene Bridge Server through version 1.10.3. The local Socket.IO server accepts WebSocket connections without validating the Origin header and does not require authentication tokens. This flaw enables unauthenticated attackers to connect from any web page visited by the victim, hijack the single-client WebSocket slot, intercept and inject automation commands, exfiltrate command-payload data, or terminate the server by sending a query parameter MIDSCENE_BRIDGE_SIGNAL_KILL. The vulnerability is fixed in a later commit (86f4118), but no official patch or advisory details are provided in this data.
Potential Impact
An attacker can remotely hijack active bridge sessions without authentication by exploiting the lack of Origin validation in WebSocket connections. This can result in unauthorized command injection, data exfiltration, and denial of service by forcibly terminating the server. The vulnerability affects confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability is fixed in commit 86f4118, so applying the fix from this commit or upgrading beyond version 1.10.3 is recommended once official patches or releases are available. Until then, restricting WebSocket access to trusted origins or network segments may reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-07T14:39:14.062Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4ea886c9d9e3dbe3a5252d
Added to database: 07/08/2026, 19:44:06 UTC
Last enriched: 07/16/2026, 10:13:53 UTC
Last updated: 08/22/2026, 10:52:10 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.