CWE-942: Permissive Cross-domain Security Policy with Untrusted Domains
The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.
111 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-34449 — SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
- CVE-2026-28792 — Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
- CVE-2026-30924 — qui CORS Misconfiguration: Arbitrary Origins Trusted
- CVE-2026-1181 — Altium 365 Over-Permissive CORS Configuration Allows Credentialed Cross-Origin Workspace Access
- CVE-2026-22812 — OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
- CVE-2025-30354 — Bruno ignores Safe-Mode in Asserts expressions
- CVE-2024-49763 — PlexRipper allows API leak due to open CORS policy
- CVE-2026-59726 — Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
- CVE-2026-33043 — AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
- CVE-2026-33010 — mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
- CVE-2026-32610 — Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
- CVE-2025-57755 — claude-code-router CORS. misconfiguration
- CVE-2024-41659 — GHSL-2024-034: memos CORS Misconfiguration in server.go
- CVE-2024-41657 — GHSL-2024-035: Casdoor CORS misconfiguration
- CVE-2026-46409 — OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
- CVE-2026-53649 — Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
- CVE-2026-9739 — Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-
- CVE-2026-61736 — LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
- CVE-2026-34200 — Nhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network Port
- CVE-2026-44895 — GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all GitLab tools
Recently published
- CVE-2026-12962 — A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local
- CVE-2026-84452 — Windows ML CLI: CORS misconfig enables localhost RCE
- CVE-2026-53649 — Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
- CVE-2026-82291 — HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials
- CVE-2026-82287 — Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials
- CVE-2026-53656 — FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data
- CVE-2026-63407 — Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses
- CVE-2026-68517 — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
- CVE-2026-74881 — openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins
- CVE-2026-18676 — Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost admin
- CVE-2026-46409 — OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
- CVE-2026-70604 — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
- CVE-2026-65310 — Missing authentication and permissive CORS policy
- CVE-2026-66005 — Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding
- CVE-2026-15966 — Improper CORS handling in MOVEit Transfer
- CVE-2026-21761 — CORS Misconfiguration in DevOps Loop
- CVE-2024-23578 — HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS)
- CVE-2026-62387 — Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin
- CVE-2026-61736 — LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
- CVE-2026-8919 — Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local us