FixVibe

// sondagens / holofote

Configuração errada de CORS

Access-Control-Allow-Origin permissivo mais credenciais significa que sua API é a API de todo mundo.

What it is

CORS is one of the trickiest security controls on the web because it inverts the usual security mental model. Same-origin policy is the browser saying 'no by default'; CORS is the server saying 'yes, but only to these origins.' Configure that 'yes' wrong and the browser gleefully hands attacker-controlled JavaScript the ability to read authenticated API responses. The bug is invisible from your application logs — it lives entirely in response headers — and it's been written into countless tutorials in the form of 'just set Access-Control-Allow-Origin to *' to make the demo work. That demo ships to production more often than anyone wants to admit.

How it happens

CORS issues appear when a site grants browser cross-origin access too broadly, especially with credentials. That can let another origin read data that was meant to stay within the application.

What an attacker gets

Cross-origin authenticated data exfiltration. The victim visits `attacker.tld`. JavaScript on `attacker.tld` makes a credentialed request to your API. The browser attaches the victim's session cookie. Your API responds with their data. CORS misconfiguration says 'this origin can read it,' so attacker JS reads the body and exfiltrates. The user never knew anything happened. Account data, billing info, message history — anything reachable from a logged-in session is on the table.

// what fixvibe reports

What FixVibe reports

Runs in active scans of a domain you have verified you own, on Hobby and above. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Maintain an explicit allowlist of trusted origins. The right shape: a `Set<string>` of canonical origins, with an exact-match check before echoing into `Access-Control-Allow-Origin`. The wrong shape: any code path that touches `req.headers.origin` and uses regex. Never combine `Allow-Credentials: true` with a wildcard origin (the spec rejects it but custom middleware sometimes ignores the spec). Reject `Origin: null` outright unless you have a specific cross-origin sandbox use case, in which case audit it carefully. Use the same CORS configuration in dev, staging, and production — drift between environments is where the prod bugs come from. For new APIs, default to no-CORS and add origins one at a time. As a sanity check, attempt a `fetch('https://yourapi.com/me', { credentials: 'include' })` from `https://example.com`'s console — if you can read the response body, you have a finding.

// rode no seu próprio app

Continue publicando enquanto o FixVibe vigia.

Verify you own the domain, then run active checks alongside the passive ones.

Sondagens ativas
138
testes nessa categoria
módulos
58
checks dedicados de sondagens ativas
verified domains
130+
active checks after verification
Verify your domain →

// checks atuais · fixes práticos · publique com confiança

Configuração errada de CORS: what it is and how to fix it · FixVibe