GSSA-2026-04-RSDKJ2GITLAB-GSSA-2026-04-RSDKJ2April 25, 20266.5 Medium
Permissive CORS configuration allows credentialed cross-origin requests in cobc-events
cobc-events <1.0.1 enabled CORS with the default `cors()` configuration, accepting any `Origin`. Combined with the JWT cookie, this allowed cross-origin sites to issue authenticated requests against the API.
Affected (1)
- gelhaus-solutionscobc-events
- ≥ 0.0.0Fixed in 1.0.1
Mitigations
Workarounds
- Place the application behind a reverse proxy that strips or validates the `Origin` header.
- Block cross-origin browser traffic at the WAF until upgrade.
Solutions
- Upgrade cobc-events to 1.0.1 or later.
- Set `BASE_URL`, `FRONTEND_URL`, and `ALLOWED_DOMAINS` to the canonical hostnames.
Overview
cobc-events <1.0.1 enabled CORS with the default cors() configuration, accepting any Origin. Combined with the JWT cookie, this allowed cross-origin sites to issue authenticated requests against the API.
Severity
CVSS v3
6.5 Medium
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- Required
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- None
- Availability
- None
Weaknesses (2)
References (2)
- Patch in src/app.js (Patch)
- CWE-942 (Third-party advisory)
Credits (5)
- Enno GelhausFinder · egelhaus@ennogelhaus.de
- Enno GelhausAnalyst · egelhaus@ennogelhaus.de
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausRemediation reviewer · egelhaus@ennogelhaus.de
- Claude (Anthropic) — automated audit assistantTool · https://claude.com
Context
Impacts
Cross-origin information disclosure of authenticated API responses
Timeline
- 04/25/2026 00:00
Internal security audit started
- 04/25/2026 06:00
Vulnerability identified during audit
- 04/25/2026 12:00
Patch developed and merged to main
- 04/25/2026 14:00
cobc-events 1.0.1 released
- 04/25/2026 15:00
Advisory published