Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hmm-4crw-vm2c

Опубликовано: 21 авг. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.1
CVSS3: 0

Описание

@musistudio/claude-code-router has improper CORS configuration

Impact

Due to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this misconfiguration to steal credentials, abuse accounts, exhaust quotas, or access sensitive data.

Patches

The issue has been patched in v1.0.34.

Пакеты

Наименование

@musistudio/claude-code-router

npm
Затронутые версииВерсия исправления

< 1.0.34

1.0.34

EPSS

Процентиль: 21%
0.00067
Низкий

8.1 High

CVSS4

0 Low

CVSS3

Дефекты

CWE-200
CWE-942

Связанные уязвимости

nvd
6 месяцев назад

claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this misconfiguration to steal credentials, abuse accounts, exhaust quotas, or access sensitive data. The issue has been patched in v1.0.34.

EPSS

Процентиль: 21%
0.00067
Низкий

8.1 High

CVSS4

0 Low

CVSS3

Дефекты

CWE-200
CWE-942