CVE-2026-18825

Summary

An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.

Affected Software

VendorProductVersion RangeStatus
github.com/antonoconnect-cors0 <= 0.5.6affected

Weaknesses

  • CWE-346: CWE-346

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References