Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-62283: Nezha Terminal/File Manager Session Hijacking via WebSocket
CVE-2026-62283 · published 13 days ago
Summary
Nezha's terminal and file manager features have a security flaw that allows an attacker to take control of a session on a remote server. This can happen if an attacker learns the ID of a live session and can connect to the server. This issue was fixed in Nezha version 2.0.10, but earlier versions are vulnerable. If you're using Nezha, make sure you're running the latest version to stay secure.
What to do
- Update github.com nezhahq to version 2.0.10.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Go | nezhahq | github.com/nezhahq/nezha | >= 1.14.13 |
| go | github.com | nezhahq |
>= 1.14.13, <= 1.14.14 >= 2.0.0, <= 2.0.9 Fix: upgrade to 2.0.10
|
| – | nezhahq | nezha | >= 1.14.13, <= 1.14.14 |
Original advisory text
Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to their creating user, and `GET /ws/terminal/:id` and `GET /ws/file/:id` only check whether the supplied UUID exists. An authenticated RoleMember who obtains a live stream UUID from logs, browser history, referer data, or telemetry can attach to another user's terminal or file-manager session, read and write target-server files, and execute shell commands. This issue is fixed in version 2.0.10.
References
- https://github.com/nezhahq/nezha/security/advisories/GHSA-q6xx-5vr8-p898
- https://github.com/advisories/GHSA-q6xx-5vr8-p898
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62283... Vendor Advisory
- https://github.com/nezhahq/nezha/commit/6661d6a7fc1c269f55c7f4e775082ad23fbe0f54 Patch
- https://github.com/nezhahq/nezha/releases/tag/v2.0.10 URL
- https://nvd.nist.gov/vuln/detail/CVE-2026-62283 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
CWE-862Missing Authorization
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen26 Jun 2026
Sources
GHSA-q6xx-5vr8-p898 · GHSA
CVE-2026-62283 · OSV
GO-2026-5821 · OSV
CVE-2026-62283 · MITRE
CVE-2026-62283 · NVD
Monitor software like this
Free during beta