Origin Validation Error in connect-xcors npm Package Affects Web Applications
CVE-2026-18825
5.3MEDIUM
What is CVE-2026-18825?
The connect-xcors npm package exhibits an Origin Validation Error in its middleware. This flaw allows attackers to bypass origin verification, which could enable unauthorized cross-domain authenticated requests. As a result, compromised applications may be susceptible to various security threats, potentially exposing sensitive data or enabling further exploitation by malicious actors. It is crucial for developers using the connect-xcors package to assess their implementations and upgrade to the latest version to mitigate this vulnerability.
Affected Version(s)
connect-cors 0 <= 0.5.6
