Two remotely exploitable flaws disclosed in ericc-ch copilot-api up to 0.7.0
Public disclosures describe two vulnerabilities in the open-source copilot-api project (versions up to 0.7.0): a permissive cross-domain policy in the cors function of src/server.ts at the token endpoint, and reliance on reverse DNS resolution via a manipulated Host header on the /token endpoint. Both are remotely exploitable and exploit details have been made public.
Disclosed 20 April 2026 · Record updated 13 September 2026
Impact
Remote attackers could abuse a permissive cross-domain policy with untrusted domains at the token endpoint and manipulate the Host header where the service relies on reverse DNS resolution; exploits are publicly available.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-6662
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-6874
