WhisperX tag archive

#InsecureSkipVerify

This page collects WhisperX intelligence signals tagged #InsecureSkipVerify. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-28 18:54:13 · GitHub Issues

1. Critical WebSocket Origin Check Disabled in Orbit Server Enables Cross-Site Hijacking

A critical security misconfiguration has been identified in the Orbit server codebase, leaving production deployments exposed to Cross-Site WebSocket Hijacking (CSWSH). The vulnerability stems from `InsecureSkipVerify: true` being set on the WebSocket `Accept` call in `cmd/server/main.go`, which disables origin validat...