Kavach

Check · Operational hygiene · default severity high

CORS policy

What Kavach checks

Which other websites the browser lets read your responses.

Why it matters

A CORS policy that reflects any origin (especially with credentials) lets a malicious site read your users' logged-in data via their browser.

How an attacker uses it

  1. Victim is logged into your site and visits an attacker's page.
  2. That page makes a request to your API from the victim's browser.
  3. Your CORS header reflects the attacker's origin, so the browser hands them your user's private response.

How to fix it

Never echo back the request Origin. Allow only a fixed list of your own origins, and only send credentials to those.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously