Skip to content
Threat Feed

Tag

CORS

15 briefs RSS
high advisory

Grav API Plugin Vulnerable to CORS Misconfiguration Allowing Data Exposure and Unauthorized Operations

The Grav API plugin before version 1.0.0-rc.16 contains a CORS misconfiguration that sets `Access-Control-Allow-Origin: *` by default, enabling an attacker to perform authenticated cross-origin requests from a malicious website after obtaining a valid API token, leading to sensitive data exfiltration and unauthorized write operations.

Grav API plugin web-vulnerability cors misconfiguration data-exfiltration rce-potential
1r 3t 1c
high advisory

CVE-2026-56400 open-webui Cross-Origin Resource Sharing Misconfiguration Leads to RCE

A cross-origin resource sharing (CORS) misconfiguration in open-webui versions prior to 0.3.14 allows remote attackers to achieve arbitrary code execution by crafting malicious cross-site requests that an authenticated administrator user visits.

open-webui cve vulnerability web-exploitation cors rce
3t 1c
critical advisory

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

Joro's default proxy mode (versions ≤ v1.1.0) is vulnerable to unauthenticated remote code execution (CVE-2026-53649) via a local API on `127.0.0.1:9090` that allows cross-origin JavaScript to upload a malicious native plugin and trigger a system restart, leading to RCE as the operator's user from a single page visit.

Joro rce web-exploitation vulnerability javascript cross-origin cors
2r 5t 1i
high advisory

CVE-2026-58656 - Grav API Plugin Cross-Origin Authentication Bypass and Account Takeover

A critical vulnerability, CVE-2026-58656, in the Grav API plugin before v1.0.0-rc.16 allows unauthenticated attackers to perform fully authenticated cross-origin API requests by leveraging leaked JWT tokens via the `?token=` URL query parameter and the `Access-Control-Allow-Origin: *` response header, potentially leading to persistent backdoor super-admin accounts and sensitive data exfiltration.

Grav API plugin grav api-plugin jwt cors remote-code-execution web-vulnerability
1r 3t 1c
high advisory

Windows-MCP Unauthenticated PowerShell Control via HTTP Transports

Windows-MCP versions prior to 0.7.5 are vulnerable to unauthenticated PowerShell control via HTTP transports due to wildcard CORS and missing authentication, allowing a remote attacker to execute arbitrary PowerShell commands as the user running Windows-MCP.

windows-mcp remote-code-execution CORS
2r 1t
high advisory

Open WebUI CORS Misconfiguration and Session Validation Vulnerability Leads to RCE

Open WebUI version v0.3.10 has a CORS misconfiguration and session validation issue that can lead to remote code execution due to a one-click attack against admin users.

open-webui cors rce session-management
2r 1t
critical advisory

SiYuan Knowledge Management System RCE via Malicious Website

SiYuan versions prior to 3.6.2 are vulnerable to remote code execution (RCE) via a malicious website exploiting a permissive CORS policy to inject a JavaScript snippet, leading to arbitrary code execution within the application's Node.js context.

cve-2026-34449 rce siyuan cors
2r 1t 1c
high advisory

Glances XML-RPC Server Cross-Origin Information Disclosure

The Glances XML-RPC server exposes sensitive system information due to a permissive CORS policy and missing Content-Type validation, enabling attackers to bypass CORS restrictions and steal data like hostnames, OS details, IP addresses, and process lists.

glances cors information-disclosure vulnerability
2r 3t 1i
high advisory

GitLab MCP Server Unauthenticated Access via SSE Transport

The @yoda.digital/gitlab-mcp-server's SSE transport lacks authentication and uses wildcard CORS, enabling unauthenticated attackers to execute arbitrary GitLab API calls using the operator's GitLab PAT, including destructive operations.

@yoda.digital/gitlab-mcp-server gitlab auth-bypass sse cors vulnerability
2r 2t
high advisory

AVideo CORS Origin Reflection with Credentials Leads to Account Takeover

The AVideo platform is vulnerable to CORS origin reflection, allowing attackers to steal user PII, livestream keys, and perform unauthorized actions by exploiting the permissive `allowOrigin` function on sensitive API endpoints.

AVideo cors account-takeover web-application
2r 4t 3i
high advisory

Glances Cross-Origin Information Disclosure via Unauthenticated REST API

Glances versions before 4.5.4 are vulnerable to cross-origin information disclosure, where a malicious website can retrieve sensitive system information from a running Glances instance due to a permissive CORS policy on the `/api/4/all` endpoint.

Glances information-disclosure cors webserver
2r 3t 1c
high advisory

WWBN AVideo CORS Vulnerability (CVE-2026-41057)

WWBN AVideo versions 29.0 and below are vulnerable to cross-origin credentialed requests to API endpoints due to an incomplete CORS origin validation fix, potentially exposing sensitive user data.

AVideo CVE-2026-41057 CORS webserver
2r 1t 1c
high advisory

WWBN AVideo Cross-Origin Request Vulnerability (CVE-2026-41056)

WWBN AVideo versions 29.0 and below are vulnerable to cross-origin request attacks (CVE-2026-41056) due to improper handling of Origin headers and session cookies, allowing unauthorized access to user data and system modifications.

AVideo cve cors credential-access
2r 1t 1c
high advisory

Jupyter Server CORS Origin Validation Bypass via Regex

Jupyter Server versions 2.17.0 and earlier are vulnerable to a CORS origin validation bypass due to improper use of `re.match()` in validating the Origin header against the `allow_origin_pat` configuration, allowing attackers to bypass CORS restrictions.

jupyter-server cors origin-validation regex web-application
2r 1t
medium advisory

ericc-ch copilot-api Permissive Cross-Domain Policy Vulnerability (CVE-2026-6662)

CVE-2026-6662 is a vulnerability in ericc-ch copilot-api up to 0.7.0, specifically in the cors function of src/server.ts, leading to a permissive cross-domain policy that can be remotely exploited for cross-domain attacks.

copilot-api CORS Cross-Site Scripting API Vulnerability
2r 1t 1c 2i