Origin Validation Error in connect-xcors npm Package Affects Web Applications
CVE-2026-18825

5.3MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-18825?

The connect-xcors npm package exhibits an Origin Validation Error in its middleware. This flaw allows attackers to bypass origin verification, which could enable unauthorized cross-domain authenticated requests. As a result, compromised applications may be susceptible to various security threats, potentially exposing sensitive data or enabling further exploitation by malicious actors. It is crucial for developers using the connect-xcors package to assess their implementations and upgrade to the latest version to mitigate this vulnerability.

Affected Version(s)

connect-cors 0 <= 0.5.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.