Exploit for CVE-2025-47910

When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.

Published: 2025-09-22

CVSS: 5.4

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Download Exploit for CVE-2025-47910 here:

Use Tor Browser to access .onion links.

Check our team here:

https://tatramed.sk/exploit-563-cve-2013-2251/

https://tatramed.sk/exploit-1064-cve-2024-33042/

https://tatramed.sk/exploit-817-cve-2025-41232/

https://tatramed.sk/exploit-441-cve-2025-9039/