CVE-2026-6662 PUBLISHED

ericc-ch copilot-api Token Endpoint server.ts cors cross-domain policy

Assigner: VulDB
Reserved: 20.04.2026 Published: 20.04.2026 Updated: 20.04.2026

A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results in permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor ericc-ch
Product copilot-api
Versions
  • Version 0.1 is affected
  • Version 0.2 is affected
  • Version 0.3 is affected
  • Version 0.4 is affected
  • Version 0.5 is affected
  • Version 0.6 is affected
  • Version 0.7.0 is affected

Credits

  • Yu_Bao (VulDB User) reporter

References

Problem Types

  • Permissive Cross-domain Policy with Untrusted Domains CWE
  • Origin Validation Error CWE