Back to Skills

cors-cross-origin-misconfiguration

CORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed browser reads, origin reflection, preflight policy bugs, and browser-based access to authenticated APIs.

1,281stars175forksUpdated 7/5/2026

Security Assessment

Safe(100/100)
Security Score100/100

About cors-cross-origin-misconfiguration

CORS Cross-Origin Misconfiguration is a security testing playbook for finding and exploiting flawed cross-origin resource sharing policies. It is meant to be loaded when responses carry Access-Control-Allow-Origin, Access-Control-Allow-Credentials, or preflight headers, when a browser-based attack path might read authenticated API responses, or when JSON endpoints appear CSRF-protected yet remain readable cross-origin. A companion SCENARIOS.md holds deeper material on JSONP hijacking, honeypot de-anonymization, same-origin policy internals, CORS-versus-JSONP comparison, and a dual-site attack lab.

The skill organizes testing around high-value misconfiguration classes: wildcard Access-Control-Allow-Origin combined with credentials, reflected arbitrary origins, weak allowlists (suffix, prefix, substring, regex, or case-matching errors), acceptance of the null origin, overbroad preflight trust, and internal or admin APIs readable cross-origin. A quick triage sends crafted Origin headers, tests with and without credentials, probes allowlist bypasses, and chains readable sensitive data to account or tenant impact.

Several concrete techniques are detailed with proof-of-concept code. Null-origin exploitation uses a sandboxed iframe (or data and file contexts) to send Origin: null so that a reflecting server leaks a credentialed response. A subdomain XSS to CORS bypass chain shows how an XSS on any target.com subdomain, combined with same-site cookies and a subdomain-trusting allowlist, yields full authenticated API reads. A Vary: Origin caching section explains CORS cache poisoning when a reflected origin is cached by a CDN or proxy without varying on origin, plus curl-based detection. A regex-bypass table enumerates flawed origin-validation patterns and payloads, including unicode homoglyph tricks, and a final section covers wildcard CORS on internal-network APIs. Related routes point to CSRF, OAuth/OIDC, and API/JWT skills.

FAQ

When should I load this skill?

When responses contain Access-Control-Allow-Origin, Access-Control-Allow-Credentials, or preflight headers, when a browser-based path could read authenticated API responses, or when JSON endpoints look CSRF-safe but are readable cross-origin.

What misconfiguration classes does it check?

Wildcard origin with credentials, reflected arbitrary origins, weak allowlists, acceptance of the null origin, overbroad preflight trust, and internal or admin APIs readable cross-origin.

How is a null origin exploited?

A sandboxed iframe (or a data or file context) sends Origin: null; if the server reflects or allowlists null with credentials, an attacker's page can read the credentialed response.

What is the Vary: Origin caching issue?

When a server reflects the origin but omits Vary: Origin, a CDN or proxy can cache and serve an attacker's Access-Control-Allow-Origin to victims - CORS cache poisoning - which curl requests can detect.

Where do JSONP hijacking and same-origin-policy deep dives live?

In the companion SCENARIOS.md, which also covers honeypot de-anonymization, CORS-versus-JSONP comparison, exploitation payloads, and a dual-site attack lab setup.

All Files

2 files
SKILL.md9.3 KB
View
SCENARIOS.md4.9 KB
View

Install cors-cross-origin-misconfiguration

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill