CVE-2026-18825: Origin validation error in the connect-xcors npm package
Published Sep 28, 2026
·Updated
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
Affected Software
1 affected component
npm/connect-xcors
Event History
Sep 28, 2026
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Applications that use the connect-xcors npm package middleware and rely on its origin verification for authenticated cross-domain requests are the relevant exposure group.
2
What does exploitation allow an attacker to do?
An attacker can bypass the middleware's origin verification and perform an authenticated request from a different domain.