Description
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized cross‑domain authenticated request
Action: Update
AI Analysis

Impact

An Origin Validation Error in the middleware of the connect-xcors npm package permits an attacker to bypass the normal origin check and send a cross‑domain request that carries authenticated credentials. This flaw enables an attacker to execute actions on the server as a legitimate user, potentially exposing sensitive data or changing state without authorization. The weakness is consistent with CWE‑346, which describes improper validation of input that should be trusted as an origin of a request.

Affected Systems

The vulnerability affects applications that use the connect-cors middleware published by github.com/antono:connect-cors. No specific version range is listed in the entry, so any deployment that has not yet upgraded is considered affected until a fix is applied.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity impact. No EPSS information is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not yet been reported. Attackers would need to influence a client to send a maliciously crafted request to the vulnerable server, typically by hosting a malicious page that directs the target browser to issue a cross‑origin request. Successful exploitation would require that the server accepts credentials and that the attacker can lure a user into visiting the malicious origin. Based on the description, the likely attack vector is a purely remote web‑based interaction without local exploitation of the host system.

Generated by OpenCVE AI on September 28, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the connect-cors npm package to the latest release that includes the origin validation fix.
  • Add your own origin‑whitelist logic to the Express application so that only explicitly permitted origins are accepted, overriding the library defaults.
  • Perform cross‑origin request tests from a controlled malicious origin to confirm that the whitelist and the package no longer allow the bypass.

Generated by OpenCVE AI on September 28, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
Title Origin validation error in the connect-xcors npm package
Weaknesses CWE-346
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TCS-CERT

Published:

Updated: 2026-09-28T13:31:27.979Z

Reserved: 2026-08-04T13:34:14.440Z

Link: CVE-2026-18825

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:05.229Z

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:21.680

Modified: 2026-09-28T14:17:15.453

Link: CVE-2026-18825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:45:02Z

Weaknesses