CVE-2026-27192 is a critical vulnerability affecting Feathersjs versions 5.0.39 and below, where insufficient origin validation allows attackers to bypass security checks. The vulnerability stems from the use of startsWith() for origin comparison, enabling attackers to register domains that share a common prefix with allowed origins. This high-severity flaw (CVSS 8.1) can lead to full account takeover through OAuth token exfiltration in specific scenarios. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.40CPE matchmatch criteria | cpe:2.3:a:feathersjs:feathers:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.