
Proof-of-concept exploit for CVE-2022-39841 demonstrating plaintext credential leakage via unauthenticated WebSocket in Medusa. Includes blog post with technical details.
For more information please read the blog post
A critical vulnerability in Medusa allows for information leakage, including plaintext credentials, by attaching to an unauthenticated WebSocket and waiting for a user to make a configuration change.