Executive brief
@koa/cors is a middleware library that handles Cross-Origin Resource Sharing (CORS) for Koa applications. By default, when no allowed origins are configured, the middleware echoes back any origin from incoming requests in the Access-Control-Allow-Origin header, effectively disabling browser same-origin policy protections. An attacker can exploit this to conduct cross-origin attacks that would normally be blocked by the browser, potentially compromising user data or session security.
Technical details
This vulnerability is a CWE-346 (Origin Validation Error) in the @koa/cors middleware. The vulnerable code unconditionally returns an Access-Control-Allow-Origin header matching the request origin when no allowed origins are explicitly configured, which disables the browser's same-origin policy enforcement. The default configuration is insecure by design; an attacker on any origin can make requests that the browser will permit, allowing cross-origin data exfiltration or session hijacking. No user authentication or interaction is required—the vulnerability is triggered by the default middleware behavior when deployed. The fix is available in version 5.0.0, which changes the default to reject requests from unconfigured origins.
Affected products
- Koa @koa/cors before 5.0.0
Timeline
- 2023-12-11: disclosed: Advisory published on GitHub and NVD
- 2023-12-11: patched: Fixed in version 5.0.0