Skip to content

vercel dev missing Host/Origin validation #16332

@wpenistone

Description

@wpenistone

vercel dev appears to accept HTTP and WebSocket requests without validating Host or Origin against the local listen address.

We have disabled vercel dev & web access being on at the same time @ our developer tooling until this is addressed.

see https://github.com/vercel/vercel/blob/main/packages/cli/src/util/dev/server.ts

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions