Impact
The vulnerability involves improper input validation in facil.io’s WebSocket frame parser. Manipulation of the on_message argument in the websocket_on_protocol_error function bypasses validation. The description states this flaw can be triggered remotely by an attacker and an exploit has been published. Based on the description, it is inferred that malformed WebSocket frames may allow an attacker to influence runtime behavior, potentially leading to unauthorized actions.
Affected Systems
The vulnerability affects boazsegev facil.io versions up to and including 0.7.4; no later versions are known to be impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is less than 1 %, suggesting a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is remote, an exploit is published, and the flaw occurs during parsing of non‑validated WebSocket frames, the risk to systems exposing this endpoint remains significant. Administrators should treat the threat level as moderate to high when the application is reachable by untrusted actors.
OpenCVE Enrichment