vulns.co
/
GKData.io MCP

Back to Bypasses

CORS misconfiguration

Find an origin the server will trust with credentials. Confirm with the CSP/CORS checks on /utils/.

Tags: cors, access-control

Techniques

Reflected origin + credentials

Full account-data theft when credentials are allowed and any origin is echoed.

  • Origin: https://evil.com  →  ACAO: https://evil.com + ACAC: true

Null origin

Reachable from an attacker-controlled sandboxed iframe or data: document.

  • Origin: null

Weak origin match

Sloppy startsWith / endsWith / regex origin checks accept lookalike domains.

  • Origin: https://target.com.evil.com
  • Origin: https://evil-target.com
  • Origin: https://targetXcom

Trusted-subdomain XSS chain

Turns a low-value subdomain XSS into reading the main app's data.

  • XSS on any *.target.com → credentialed fetch to the main app

Non-HTTPS trust

Allows a MITM on plaintext to read cross-origin responses.

  • Origin: http://target.com