All fixes

Block null origin on private APIs

cors-auth-null

Your authenticated endpoints accept the null origin with credentials. A sandboxed iframe can claim null, read the response and take user data.

Why this matters

Your logged-in API endpoints trust null origin requests with credentials. Exploitable via sandboxed iframes, but requires crafting a specific attack page — conditionally exploitable.

Express

  1. 1 Your authenticated endpoints accept Origin: null
  2. 2 Do not whitelist null in your CORS config
javascript
// Ensure 'null' is never in your origin list
app.use(cors({
  origin: ["https://app.example.com"],  // explicit list only
}));

Does your app still have this?

Scan your domain