CRITICAL
Rob--W / cors-anywhere
CVE published 2025-09-25
CVE-2020-36851
CVE-2020-36851 debrief based on the supplied source corpus. The CVE record was published on 2025-09-25T15:16:01.503Z. This vulnerability affects Rob--W / cors-anywhere instances configured as open proxies, allowing unauthenticated external users to induce the server to make HTTP requests to arbitrary targets, potentially leading to theft of cloud credentials, unauthorized access, or data exfiltration. Def [truncated]