Vulnerabilities/

cors-anywhere vulnerable to server-side request forgery

Severity:
High

Description

Rob – W / cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to make HTTP requests to arbitrary targets (SSRF).

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
cors-anywhere
Anything's wrong? Let us know Last updated on September 26, 2025

This issue is available in SmartScanner Professional

See Pricing