Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6662

Опубликовано: 20 апр. 2026
Источник: nvd
CVSS3: 7.3
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results in permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

EPSS

Процентиль: 8%
0.00182
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 7.3
github
4 месяца назад

A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results in permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

EPSS

Процентиль: 8%
0.00182
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-346