Impact
An Origin Validation Error in the middleware of the connect-xcors npm package permits an attacker to bypass the normal origin check and send a cross‑domain request that carries authenticated credentials. This flaw enables an attacker to execute actions on the server as a legitimate user, potentially exposing sensitive data or changing state without authorization. The weakness is consistent with CWE‑346, which describes improper validation of input that should be trusted as an origin of a request.
Affected Systems
The vulnerability affects applications that use the connect-cors middleware published by github.com/antono:connect-cors. No specific version range is listed in the entry, so any deployment that has not yet upgraded is considered affected until a fix is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity impact. No EPSS information is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not yet been reported. Attackers would need to influence a client to send a maliciously crafted request to the vulnerable server, typically by hosting a malicious page that directs the target browser to issue a cross‑origin request. Successful exploitation would require that the server accepts credentials and that the attacker can lure a user into visiting the malicious origin. Based on the description, the likely attack vector is a purely remote web‑based interaction without local exploitation of the host system.
OpenCVE Enrichment