@musistudio/claude-code-router has improper CORS configuration
High severity
GitHub Reviewed
Published
Aug 21, 2025
in
musistudio/claude-code-router
•
Updated Aug 21, 2025
Description
Published to the GitHub Advisory Database
Aug 21, 2025
Reviewed
Aug 21, 2025
Published by the National Vulnerability Database
Aug 21, 2025
Last updated
Aug 21, 2025
Impact
Due to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this misconfiguration to steal credentials, abuse accounts, exhaust quotas, or access sensitive data.
Patches
The issue has been patched in v1.0.34.
References