discovered 03 Aug 2026
CORS-vulnerability-with-trusted-null-origin
→ View on GitHubThe CORS vulnerability tool demonstrates the exploitation of a null origin CORS misconfiguration in a web application, enabling attackers to exfiltrate sensitive API keys. This GitHub repository provides a comprehensive walkthrough of a proof-of-concept (PoC) attack on a sample lab site, detailing the steps and methods used to identify and exploit the vulnerability, along with suggested mitigation techniques to enhance security. Notable features include a structured guide with practical examples and screenshots to aid in understanding the exploit and its implications.