Skip to content

Repository files navigation

CORSweep 🧹

A CORS misconfig scanner that doesn't cry wolf.
Only fires when a bug is actually exploitable.

CORSweep catching a critical CORS bug


Why another CORS tool? 🤨

Real talk — I got tired of scanners flagging Access-Control-Allow-Origin: * like it's the end of the world and then me wasting 20 minutes proving it's not exploitable. So I built one that only shouts when it's actually worth shouting.

other scanners vs corsweep

The one rule that kills false positives: a reflection only counts when Access-Control-Allow-Origin exactly equals the Origin we sent. Server locks it to a fixed value? We stay quiet. * with no creds? That's a LOW, not a heart attack.


What it catches

Test The flaw Payload
reflect_arbitrary Reflects literally any origin https://cw-evil-...com
null_origin Trusts null (sandboxed iframe trick) null
http_downgrade HTTPS site trusting http:// http://target
prefix_bypass startsWith / lazy regex https://target.evil.com
suffix_bypass endsWith / unanchored regex https://eviltarget.com
unescaped_dot Someone forgot to escape the . https://targetxcom
special_char Backtick / underscore parser tricks https://target%60.evil.com
subdomain_trust Trusts any subdomain https://cw-sub.target

Severity is scored on whether Access-Control-Allow-Credentials: true is actually there — so a CRITICAL genuinely means "someone can read your logged-in user's data from evil.com." Not vibes. Real impact.


Get it running (30 seconds)

git clone https://github.com/suhelkathi/corsweep
cd corsweep
pip install -r requirements.txt

Use it

# quick single shot
python3 corsweep.py -u https://api.target.com/user/profile

# authenticated scan — THIS is where the CRITICALs live 🔥
python3 corsweep.py -u https://api.target.com/me -c "session=abcd1234"

# whole list, hide the noise, save JSON for your report
python3 corsweep.py -l hosts.txt --only-vuln --json out.json

# pipe it through Burp like a civilised person
python3 corsweep.py -u https://target -k --proxy http://127.0.0.1:8080

Confirm it by hand

curl -s -I https://api.target.com/me \
  -H "Origin: https://cw-evil-8f3a2b.com" \
  -H "Cookie: session=..." | grep -i access-control

Evil origin echoed back + Access-Control-Allow-Credentials: true? Ship the finding. 📸


⚠️ Disclaimer

Only run this on stuff you're allowed to test. A signed scope or a bug bounty program. That's it. Getting a CORS finding is cool. A legal notice is not.


Built by @suhelkathi · if this saved you time, smash that ⭐

About

A CORS misconfig scanner that keeps false positives near zero

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages