Impact
Midscene Bridge Server versions up to and including 1.10.3 have a CORS misconfiguration that allows an attacker to open an unauthenticated cross‑origin WebSocket connection to the local Socket.IO server. This flaw is a missing authentication (CWE‑306) and an inadequate input that performs no Origin header validation and requires no authentication token. The attacker can hijack an active bridge session, intercept and inject automation commands, exfiltrate command‑payload data, or unconditionally terminate the server by supplying the MIDSCENE_BRIDGE_SIGNAL_KILL query parameter, resulting in loss of confidentiality, integrity, and availability for the session.
Affected Systems
The vulnerability occurs in the Midscene Bridge Server product produced by web‑infra‑dev. All releases up to and including 1.10.3 are affected. Any installation that has not applied the patch from commit 86f4118 remains vulnerable.
Risk and Exploitability
The CVSS score of 7.6 signifies high severity, while the EPSS score of <1% indicates a low probability of exploitation. Nevertheless, the flaw can be triggered remotely from a victim’s browser through a cross‑origin WebSocket connection and requires no authentication, making the attack vector straightforward. The vulnerability is not listed in the CISA KEV catalog, but its remote nature and ease of exploitation keep its risk substantial.
OpenCVE Enrichment