CVE-2026-77360 | middleapi orpc up to 1.14.7 CORS cors.ts cross-domain policy
A vulnerability, which was classified as problematic, was found in middleapi orpc up to 1.14.7. The impacted element is an unknown function of the file packages/server/src/plugins/cors.ts of the component CORS. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.
This vulnerability is tracked as CVE-2026-77360. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More