vulns.co
/
GKData.io MCP

Back to Reports

An API reflected the caller's origin and allowed credentials

A reflected origin is inventory until a credentialed response is readable from another site. This card does not repeat the origin that was tested.

Editorial decision card. This page links to a source-verified public disclosure and contains only original defensive analysis. It does not mirror upstream HTML, payloads, attachments, private submissions, or exploit steps.
Original severity
Medium (5.7) source-reported; not rescored by vulns.co
Public source
hackerone disclosure
Program / vendor
Semrush
Product / surface
Authenticated Semrush API
Weakness
CORS misconfiguration
Affected boundary
A credentialed API response and an origin the caller chose
Disclosure date
2017-12-17
Public status checked
2026-09-28
Public attribution
bughuntermate

What the evidence established

The disclosed report shows the API reflecting a caller-supplied origin and allowing credentials. A later comment on the same report says the header was then limited to the site's own origin. Severity on the disclosure is Medium (5.7).

Why the impact was credible

The source reported that a third-party page could read an authenticated API response.

Durable engineering lesson

A reflected origin is inventory until a credentialed response is readable from another site. This card does not repeat the origin that was tested.

Control pattern

Allow credentials only for an explicit origin list. Do not copy the request Origin into the response.

Primary public disclosure

Read the original source ↗

Upstream availability and wording can change. Public status was last checked 2026-09-28.