WhisperX tag archive

#CWE-346

This page collects WhisperX intelligence signals tagged #CWE-346. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-11 13:22:35 · GitHub Issues

1. Critical CORS Misconfiguration in Production API: Origin Header Bypass Exposes Server to Unrestricted Cross-Domain Requests

A critical security misconfiguration in a production API's CORS (Cross-Origin Resource Sharing) policy is actively bypassing origin validation, allowing unauthorized cross-domain requests. The vulnerability, classified as a P1 (Medium Severity, Urgent) issue, stems from code in `server/src/utils/cors-config.ts` that ex...