{"id":"CVE-2025-57755","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-57755","summary":"@musistudio/claude-code-router has improper CORS configuration","details":"### Impact\nDue to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this misconfiguration to steal credentials, abuse accounts, exhaust quotas, or access sensitive data.\n\n### Patches\nThe issue has been patched in v1.0.34.","published":"2025-08-21T14:54:24Z","modified":"2025-08-21T20:12:20.629399Z","cvss":{"score":0,"severity":"NONE","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@musistudio/claude-code-router","fixedVersion":"1.0.34"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/musistudio/claude-code-router/security/advisories/GHSA-8hmm-4crw-vm2c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57755"},{"type":"WEB","url":"https://github.com/musistudio/claude-code-router/issues/549"},{"type":"PACKAGE","url":"https://github.com/musistudio/claude-code-router"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-08-21T20:12:20.629399Z"}}