Check · Operational hygiene · default severity high
CORS policy
What Kavach checks
Which other websites the browser lets read your responses.
Why it matters
A CORS policy that reflects any origin (especially with credentials) lets a malicious site read your users' logged-in data via their browser.
How an attacker uses it
- Victim is logged into your site and visits an attacker's page.
- That page makes a request to your API from the victim's browser.
- Your CORS header reflects the attacker's origin, so the browser hands them your user's private response.
How to fix it
Never echo back the request Origin. Allow only a fixed list of your own origins, and only send credentials to those.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.