GroupSession Missing Origin Validation in WebSockets Vulnerability

Vulnerability

A vulnerability exists in GroupSession Free edition prior to 5.3.0, GroupSession byCloud prior to 5.3.3, and GroupSession ZION prior to 5.3.2, where WebSocket connections lack proper origin validation. This flaw can lead to the exposure of chat information sent to users who access a crafted page.

Impact

Exploitation of this vulnerability could result in the unauthorized exposure of chat information to users.

Remediation

Users are advised to update to the latest version of GroupSession. The latest version can be downloaded from the GroupSession website. Note that GroupSession byCloud has already addressed this vulnerability.

Added: Dec 12, 2025, 5:47 AM
Updated: Dec 12, 2025, 5:47 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.4
exploitability
6.0
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.