Skip to content

Extension does not bound to localhost IP #3091

Open
@b0trob

Description

@b0trob

The service bounds to 0.0.0.0:5500 which is insecure if used along with remote-ssh, when connecting remotely to a server it will bound to 0.0.0.0:5500 on the remote host, if such server has a public ip configured the http server will be publicly exposed.

All local:

Image

Image

The actual setting is only being applied on where the browser points to:

Image

Now, this will also happen when connecting remotely:

Image

Remote host:

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions