An API reflected the caller's origin and allowed credentials
A reflected origin is inventory until a credentialed response is readable from another site. This card does not repeat the origin that was tested.
- Original severity
- Medium (5.7) source-reported; not rescored by vulns.co
- Public source
- hackerone disclosure
- Program / vendor
- Semrush
- Product / surface
- Authenticated Semrush API
- Weakness
- CORS misconfiguration
- Affected boundary
- A credentialed API response and an origin the caller chose
- Disclosure date
- 2017-12-17
- Public status checked
- 2026-09-28
- Public attribution
- bughuntermate
What the evidence established
The disclosed report shows the API reflecting a caller-supplied origin and allowing credentials. A later comment on the same report says the header was then limited to the site's own origin. Severity on the disclosure is Medium (5.7).
Why the impact was credible
The source reported that a third-party page could read an authenticated API response.
Durable engineering lesson
A reflected origin is inventory until a credentialed response is readable from another site. This card does not repeat the origin that was tested.
Control pattern
Allow credentials only for an explicit origin list. Do not copy the request Origin into the response.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-28.