{"id":"CVE-2026-18825","published":"2026-09-28T13:17:21.680","lastModified":"2026-09-28T21:03:44.987","description":"An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-346"],"vendors":[],"products":[],"references":[{"url":"https://cds.thalesgroup.com/en/tcs-cert/CVE-2026-18825","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}