hackwither_

reap / rules / transport posture

Permissive CORS policy on agent endpoint

http-cors-wildcard ASI03 Identity and Privilege Abuse severity: high

What it detects

Wildcard or reflected CORS, confirmed via a real preflight; escalates when combined with credentialed cross-origin. ASI03.

Sends a foreign Origin header; flags Access-Control-Allow-Origin: *, escalating to High if combined with Access-Control-Allow-Credentials: true.

applies to any agent endpoint over HTTP

Why it matters

Permissive CORS lets an arbitrary web origin act as the agent from a victim's browser.

OWASP ASI mapping rationale

Example finding

HIGH  http-cors-wildcard   CONFIDENCE
Permissive CORS policy on agent endpoint
Server returns Access-Control-Allow-Origin: * — any web origin can call this endpoint from a browser context. Combined with Access-Control-Allow-Credentials: true, this allows credentialed cross-origin requests, which browsers should normally block.

from a scan of reap-range, bad target

Fix

Scope Access-Control-Allow-Origin to known first-party origins; never reflect an arbitrary Origin, and never combine * with credentialed requests.

On reap-range

insecure targetbad/mcp (ACAO:* + credentials, seen on the POST response) · High
correct targetgood/mcp sends no ACAO header

Run only this check

reap -t https://your-host/mcp --authorized --include http-cors-wildcard

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.