Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Two remotely exploitable flaws disclosed in ericc-ch copilot-api up to 0.7.0

Public disclosures describe two vulnerabilities in the open-source copilot-api project (versions up to 0.7.0): a permissive cross-domain policy in the cors function of src/server.ts at the token endpoint, and reliance on reverse DNS resolution via a manipulated Host header on the /token endpoint. Both are remotely exploitable and exploit details have been made public.

Disclosed 20 April 2026 · Record updated 13 September 2026

Impact

Remote attackers could abuse a permissive cross-domain policy with untrusted domains at the token endpoint and manipulate the Host header where the service relies on reverse DNS resolution; exploits are publicly available.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-6662
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-6874