VYPR

traccar

by GitHub

CVEs (1)

  • CVE-2025-68930HigFeb 23, 2026
    risk 0.49cvss 7.1epss 0.01

    Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocket handshake. This allows a…