Description
A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results in permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Problem types
Permissive Cross-domain Policy with Untrusted Domains
Product status
0.2
0.3
0.4
0.5
0.6
0.7.0
Timeline
| 2026-04-20: | Advisory disclosed |
| 2026-04-20: | VulDB entry created |
| 2026-04-20: | VulDB entry last update |
Credits
Yu_Bao (VulDB User)
References
vuldb.com/vuln/358300 (VDB-358300 | ericc-ch copilot-api Token Endpoint server.ts cors cross-domain policy)
vuldb.com/vuln/358300/cti (VDB-358300 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/794601 (Submit #794601 | ericc-ch copilot-api 0.7.0 Cross-Origin Token Theft via Wildcard CORS & Open Token Endpoint)
github.com/August829/CVEP/issues/31