Taipy Cross-Site WebSocket Hijacking via Wildcard socket.io CORS

Release Date: 3rd September 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and data science/development teams that build or operate web applications using the Taipy Python framework. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-85183 is a critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability in Taipy, an open-source Python framework (19,200+ GitHub stars) published by Avaiga that lets data scientists and developers turn data and AI algorithms into production-ready web applications, including interactive dashboards and what-if scenario tools.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-85183
  2. https://github.com/Avaiga/taipy