Cross-Origin Resource Sharing (CORS) is a browser mechanism that relaxes the Same-Origin Policy (SOP) to allow web applications running at one origin to make authenticated requests to an API at a different origin. Misconfiguring CORS headers is one of the quickest ways to expose authenticated user data to third-party attackers.
The deadly combination: reflected origin with credentials
The browser's Same-Origin Policy strictly prohibits setting `Access-Control-Allow-Origin: *` while simultaneously setting `Access-Control-Allow-Credentials: true`. To work around this restriction, developers frequently write dynamic reflection logic that blindly reads the incoming `Origin` header and echoes it back in the response.
- Origin reflection: echoing any arbitrary `Origin: https://evil-attacker.com` alongside `Access-Control-Allow-Credentials: true`, enabling malicious sites to steal authenticated data via simple JavaScript `fetch()` calls.
- Null origin trust: allowing `Origin: null`, which attackers can trigger using sandboxed iframes (`<iframe sandbox='allow-scripts'>`).
- Weak regex parsing: matching `bugsnaps.in` using regexes like `/bugsnaps.in/` without anchoring, allowing origins like `https://bugsnaps.in.evil.com` or `https://notbugsnaps.in`.
Safe CORS architecture
Maintain a strict, hardcoded server-side allowlist of trusted origins. Validate incoming Origin headers against the exact array. If the origin is not explicitly in the allowlist, do not return CORS headers at all.
BugSnaps MyPentest automatically tests CORS endpoints with diverse origin probes, identifying insecure reflection, null origin trust, and credential exposure.