AlphaDevelopmental / CORS-SOP-lab Star 4 Code Issues Pull requests The tests demonstrate all 9 common CORS misconfigurations actively: Wildcard origins Origin reflection with credentials Null origin trust Regex bypasses (prefix/suffix) Subdomain trust pivots Preflight caching issues Unsafe methods exposure Private Network Access misconfigs cors penetration ctf same-origin-policy security-training security-tools api-security vulnerability-research browser-security penetration-testing-tools security-labs cors-bypass Updated Apr 23, 2026 JavaScript