{"resultsPerPage":5,"startIndex":0,"totalResults":5,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-12T20:56:49.378","vulnerabilities":[{"cve":{"id":"CVE-2021-35206","sourceIdentifier":"cve@mitre.org","published":"2021-06-22T14:15:09.057","lastModified":"2026-06-17T03:57:17.837","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitpod before 0.6.0 allows unvalidated redirects."},{"lang":"es","value":"Gitpod versiones anteriores a 0.6.0 permite redireccionamientos no validados"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitpod:gitpod:*:*:*:*:*:*:*:*","versionEndExcluding":"0.6.0","matchCriteriaId":"B61DBCDC-355B-4580-91B4-8D95E1124CE7"}]}]}],"references":[{"url":"https://github.com/gitpod-io/gitpod/blob/main/CHANGELOG.md","source":"cve@mitre.org","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/commit/8ca431f86ae3a6f9a17afcfed51cdd065fcff1a5","source":"cve@mitre.org","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/compare/0.6.0-beta5...0.6.0","source":"cve@mitre.org","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/pull/2879","source":"cve@mitre.org","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/pull/2879#issuecomment-865662372","source":"cve@mitre.org","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/pull/4567","source":"cve@mitre.org","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/pull/4567/commits/f78b7d18e509e28e71b65bbd4dfd52c16ca57c18","source":"cve@mitre.org","tags":["Patch","Third Party Advisory"]},{"url":"https://www.gitpod.io/changelog","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/blob/main/CHANGELOG.md","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/commit/8ca431f86ae3a6f9a17afcfed51cdd065fcff1a5","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/compare/0.6.0-beta5...0.6.0","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/pull/2879","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/pull/2879#issuecomment-865662372","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/pull/4567","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/pull/4567/commits/f78b7d18e509e28e71b65bbd4dfd52c16ca57c18","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.gitpod.io/changelog","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-0957","sourceIdentifier":"report@snyk.io","published":"2023-03-03T08:15:08.613","lastModified":"2026-06-17T05:26:44.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace."}],"affected":[{"source":"report@snyk.io","affectedData":[{"vendor":"Gitpod","product":"Gitpod","versions":[{"version":"0","lessThan":"2022.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"report@snyk.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-05T19:56:47.706471Z","id":"CVE-2023-0957","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"report@snyk.io","type":"Secondary","description":[{"lang":"en","value":"CWE-1385"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitpod:gitpod:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.11.2","matchCriteriaId":"DA92F145-3FE3-4749-AA7B-648BC0588E31"}]}]}],"references":[{"url":"https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=default&orgId=71ccd717-aa2d-4a1e-942e-c768d37e9e0c&tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d","source":"report@snyk.io","tags":["Vendor Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/commit/12956988eec0031f42ffdfa3bdc3359f65628f9f","source":"report@snyk.io","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/commit/673ab6856fa04c13b7b1f2a968e4d090f1d94e4f","source":"report@snyk.io","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/pull/16378","source":"report@snyk.io","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/gitpod-io/gitpod/pull/16405","source":"report@snyk.io","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/gitpod-io/gitpod/releases/tag/release-2022.11.2","source":"report@snyk.io","tags":["Release Notes"]},{"url":"https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets/","source":"report@snyk.io","tags":["Third Party Advisory"]},{"url":"https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=default&orgId=71ccd717-aa2d-4a1e-942e-c768d37e9e0c&tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/commit/12956988eec0031f42ffdfa3bdc3359f65628f9f","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/commit/673ab6856fa04c13b7b1f2a968e4d090f1d94e4f","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/pull/16378","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/gitpod-io/gitpod/pull/16405","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/gitpod-io/gitpod/releases/tag/release-2022.11.2","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-32766","sourceIdentifier":"cve@mitre.org","published":"2023-06-05T15:15:09.143","lastModified":"2026-06-17T05:59:33.387","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-08T19:30:55.584973Z","id":"CVE-2023-32766","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitpod:gitpod:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.11.3","matchCriteriaId":"862828C1-EFDB-4680-A3BA-54F828B08C8A"}]}]}],"references":[{"url":"https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=default&tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/commit/6771283c3406586e352337675b79ff2ca50f191b","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/compare/release-2022.11.2...2022.11.3","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/pull/17559","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/releases/tag/2022.11.3","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://www.gitpod.io","source":"cve@mitre.org","tags":["Product"]},{"url":"https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=default&tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://github.com/gitpod-io/gitpod/commit/6771283c3406586e352337675b79ff2ca50f191b","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/compare/release-2022.11.2...2022.11.3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/pull/17559","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/gitpod-io/gitpod/releases/tag/2022.11.3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://www.gitpod.io","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}},{"cve":{"id":"CVE-2024-21583","sourceIdentifier":"report@snyk.io","published":"2024-07-19T05:15:10.373","lastModified":"2026-06-17T07:09:44.457","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/auth before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/public-api-server before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/server before main-gha.27122; versions of the package @gitpod/gitpod-protocol before 0.1.5-main-gha.27122 are vulnerable to Cookie Tossing due to a missing __Host- prefix on the _gitpod_io_jwt2_ session cookie. This allows an adversary who controls a subdomain to set the value of the cookie on the Gitpod control plane, which can be assigned to an attacker’s own JWT so that specific actions taken by the victim (such as connecting a new Github organization) are actioned by the attackers session."},{"lang":"es","value":"Versiones del paquete github.com/gitpod-io/gitpod/components/server/go/pkg/lib antes de main-gha.27122; versiones del paquete github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy antes de main-gha.27122; versiones del paquete github.com/gitpod-io/gitpod/install/installer/pkg/components/auth antes de main-gha.27122; versiones del paquete github.com/gitpod-io/gitpod/install/installer/pkg/components/public-api-server antes de main-gha.27122; versiones del paquete github.com/gitpod-io/gitpod/install/installer/pkg/components/server antes de main-gha.27122; Las versiones del paquete @gitpod/gitpod-protocol anteriores a 0.1.5-main-gha.27122 son vulnerables al lanzamiento de cookies debido a que falta un prefijo __Host- en la cookie de sesión _gitpod_io_jwt2_. Esto permite a un adversario que controla un subdominio establecer el valor de la cookie en el plano de control de Gitpod, que puede asignarse al propio JWT de un atacante para que las acciones específicas tomadas por la víctima (como conectar una nueva organización de Github) sean ejecutadas por La sesión de los atacantes."}],"affected":[{"source":"report@snyk.io","affectedData":[{"vendor":"n/a","product":"github.com/gitpod-io/gitpod/components/server/go/pkg/lib","versions":[{"version":"0","lessThan":"main-gha.27122","versionType":"semver","status":"affected"}]},{"vendor":"n/a","product":"github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy","versions":[{"version":"0","lessThan":"main-gha.27122","versionType":"semver","status":"affected"}]},{"vendor":"n/a","product":"github.com/gitpod-io/gitpod/install/installer/pkg/components/auth","versions":[{"version":"0","lessThan":"main-gha.27122","versionType":"semver","status":"affected"}]},{"vendor":"n/a","product":"github.com/gitpod-io/gitpod/install/installer/pkg/components/public-api-server","versions":[{"version":"0","lessThan":"main-gha.27122","versionType":"semver","status":"affected"}]},{"vendor":"n/a","product":"github.com/gitpod-io/gitpod/install/installer/pkg/components/server","versions":[{"version":"0","lessThan":"main-gha.27122","versionType":"semver","status":"affected"}]},{"vendor":"n/a","product":"@gitpod/gitpod-protocol","versions":[{"version":"0","lessThan":"0.1.5-main-gha.27122","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"report@snyk.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-19T12:27:45.663149Z","id":"CVE-2024-21583","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"report@snyk.io","type":"Secondary","description":[{"lang":"en","value":"CWE-15"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-565"}]}],"references":[{"url":"https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=%5B%E2%80%A6%5D942e-c768d37e9e0c&tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d","source":"report@snyk.io"},{"url":"https://github.com/gitpod-io/gitpod/commit/da1053e1013f27a56e6d3533aa251dbd241d0155","source":"report@snyk.io"},{"url":"https://github.com/gitpod-io/gitpod/pull/19973","source":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODCOMPONENTSSERVERGOPKGLIB-7452074","source":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODCOMPONENTSWSPROXYPKGPROXY-7452075","source":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSAUTH-7452076","source":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSPUBLICAPISERVER-7452077","source":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSSERVER-7452078","source":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JS-GITPODGITPODPROTOCOL-7452079","source":"report@snyk.io"},{"url":"https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=%5B%E2%80%A6%5D942e-c768d37e9e0c&tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/gitpod-io/gitpod/commit/da1053e1013f27a56e6d3533aa251dbd241d0155","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/gitpod-io/gitpod/pull/19973","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODCOMPONENTSSERVERGOPKGLIB-7452074","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODCOMPONENTSWSPROXYPKGPROXY-7452075","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSAUTH-7452076","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSPUBLICAPISERVER-7452077","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGITPODIOGITPODINSTALLINSTALLERPKGCOMPONENTSSERVER-7452078","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-JS-GITPODGITPODPROTOCOL-7452079","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2025-55750","sourceIdentifier":"security-advisories@github.com","published":"2025-08-29T16:15:37.173","lastModified":"2026-06-17T09:42:10.283","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Gitpod is a developer platform for cloud development environments. In versions before main-gha.33628 for both Gitpod Classic and Gitpod Classic Enterprise, OAuth integration with Bitbucket in certain conditions allowed a crafted link to expose a valid Bitbucket access token via the URL fragment when clicked by an authenticated user. This resulted from how Bitbucket returned tokens and how Gitpod handled the redirect flow. The issue was limited to Bitbucket (GitHub and GitLab integrations were not affected), required user interaction, and has been mitigated through redirect handling and OAuth logic hardening. The issue was resolved in main-gha.33628 and later. There are no workarounds."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"gitpod-io","product":"gitpod","versions":[{"version":"Gitpod Classic < main-gha.33628","status":"affected"},{"version":"Gitpod Classic Enterprise < main-gha.33628","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-29T16:02:58.230388Z","id":"CVE-2025-55750","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]}],"references":[{"url":"https://github.com/gitpod-io/gitpod/commit/a736c1b83bd781786af0da705d0acebabfba7862","source":"security-advisories@github.com"},{"url":"https://github.com/gitpod-io/gitpod/pull/20983","source":"security-advisories@github.com"},{"url":"https://github.com/gitpod-io/gitpod/security/advisories/GHSA-63fw-3jgp-2p2g","source":"security-advisories@github.com"}]}}]}