CVE-2026-18825
Origin validation error in the connect-xcors npm package
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
| CWE | CWE-346 |
| Vendor | github.com/antono |
| Product | connect-cors |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for github.com/antono connect-cors
Be the first to know when new unknown vulnerabilities affecting github.com/antono connect-cors are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
github.com/antono / connect-cors
0 โค 0.5.6