Block null origin on private APIs
cors-auth-null
Your authenticated endpoints accept the null origin with credentials. A sandboxed iframe can claim null, read the response and take user data.
Why this matters
Your logged-in API endpoints trust null origin requests with credentials. Exploitable via sandboxed iframes, but requires crafting a specific attack page — conditionally exploitable.
Frameworks
Express
- 1 Your authenticated endpoints accept Origin: null
- 2 Do not whitelist null in your CORS config
javascript
// Ensure 'null' is never in your origin list
app.use(cors({
origin: ["https://app.example.com"], // explicit list only
}));Does your app still have this?
Scan your domain