High severity8.8NVD Advisory· Published Feb 5, 2018· Updated Jun 17, 2026
CVE-2018-6651
CVE-2018-6651
Description
In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <140-3
- Range: <0.07
Patches
Vulnerability mechanics
References
3- github.com/chrisd1100/uncurl/commit/448cd13e7b18c83855d706c564341ddd1e38e769nvdPatchThird Party Advisory
- github.com/chrisd1100/uncurl/releases/tag/0.07nvdThird Party Advisory
- gist.github.com/Zenexer/ac7601c0e367d876353137e5099b18a7nvd
News mentions
0No linked articles in our index yet.