Hunt Cors

Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled origin can perform a CREDENTIALED cross-origin read of sensitive data and you have proven it in a browser. Use when testing API endpoints, SPAs, or any app emitting Access-Control-* headers.

elementalsouls 3e8c5d2 14.6 KB Updated

File contents

elementalsouls/Claude-BugHunter commit 3e8c5d2ca8

Frequently asked questions

npx skillmds@latest add elementalsouls/hunt-cors