CVE-2026-18825EPSS p6.3%

CVE-2026-18825CVE-2026-18825

Description

An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.

Scoring

EPSS0.18% probability of exploitation · percentile 6.3% · 2026-10-05T12:00:23Z
Last modified2026-09-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.