{"id":"CVE-2016-10549","aliases":["GHSA-qmv4-jgp7-mf68"],"url":"https://o3.security/vulnerability/CVE-2016-10549","summary":"Sails before 0.12.7 vulnerable to Broken CORS","details":"Affected versions of `sails` have an issue with the CORS configuration where the value of the origin header is reflected as the value for the `Access-Control-Allow-Origin` header. This may allow an attacker to make AJAX requests to vulnerable hosts through cross-site scripting or a malicious HTML Document, effectively bypassing the Same Origin Policy. \n\n## Mitigating Factors\n\nThis is only an issue when `allRoutes` is set to `true` and `origin` is set to `*` or left commented out in the sails CORS config file. \n\nThe problem can be compounded when the cors `credentials` setting is not provided, because at that point authenticated cross domain requests are possible.\n\n\n## Recommendation\n\nUpdate to version 0.12.7 or later.\n\nAs this vulnerability is primarily a user error, the patch for the vulnerability will simply cause the application to write an error message to the console when a vulnerable configuration is used in a production environment.\n\nWriting a proper CORS configuration is still the responsibility of the user, so it is necessary to check for the error message after installing the patch. Be sure you are not using `allRoutes: true` with `origin:'*'`, and that you uncomment `origin` and set it to a reasonable value. Ensure that if `origin` is set to `*` that you truly mean for all other websites to be able to make cross-domain requests to your API.\n\nLikewise, ensure `credentials` is uncommented out and set to the appropriate value. Make sure to explicitly set which origins may request resources via CORS.","published":"2018-05-31T20:29:01.830Z","modified":"2026-07-08T12:43:48.392422Z","cvss":{"score":4.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"sails","fixedVersion":"0.12.7"}],"fix":{"url":"https://github.com/balderdashy/sails/commit/0057123a0321be6758845abbeb4290bf418ce542","label":"balderdashy/sails@0057123"},"references":[{"type":"ADVISORY","url":"http://sailsjs.org/documentation/concepts/security/cors"},{"type":"ADVISORY","url":"http://sailsjs.org/documentation/reference/configuration/sails-config-cors"},{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/148"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10549"},{"type":"WEB","url":"https://github.com/balderdashy/sails/commit/0057123a0321be6758845abbeb4290bf418ce542"},{"type":"PACKAGE","url":"https://github.com/balderdashy/sails"},{"type":"WEB","url":"https://github.com/balderdashy/sails/releases/tag/v0.12.7"},{"type":"WEB","url":"https://www.npmjs.com/advisories/148"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:43:48.392422Z"}}