Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a
In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui u
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerabili
Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFi
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijack
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat
Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is config
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server d
Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoi
A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebSc
Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This
Frequently Asked Questions
What is CWE-1385?
CWE-1385 (CWE-1385) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1385?
There are 15 CVE records associated with CWE-1385 in our database. Of these, 1 are critical severity, 6 are high severity, and 7 are medium severity.
How can I protect against CWE-1385 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1385 using AI-powered security agents.
Detect CWE-1385 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1385 vulnerabilities across your infrastructure.
Get Started