FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
Why Cursor Keeps Writing Wildcard CORS Into Your Express APIs
How-ToWeb Development

Why Cursor Keeps Writing Wildcard CORS Into Your Express APIs

via Dev.to WebdevCharles Kern2h ago

TL;DR Cursor generates cors({ origin: '*' }) on nearly every Express app it builds Wildcard CORS + Bearer tokens in localStorage means any site can make authenticated requests on behalf of your users One-line fix: replace '*' with an explicit origin allowlist I was reviewing a side project last week. A Node/Express REST API built almost entirely with Cursor. The developer was sharp. The code was clean. The CORS config was a disaster. Every single endpoint was configured with app.use(cors({ origin: '*' })) . The app handled user accounts, subscription data, and a connected Stripe integration. Wide open to any origin on the internet. I've seen this exact pattern in a dozen Cursor-generated projects now. It's not a Cursor bug. It's a training data problem. The Vulnerable Code (CWE-942) Here's what Cursor produces when you ask it to add CORS to an Express app: const express = require ( ' express ' ); const cors = require ( ' cors ' ); const app = express (); app . use ( cors ({ origin : '

Continue reading on Dev.to Webdev

Opens in a new tab

Read Full Article
0 views

Related Articles

How-To

10 Things Every Software Developer Should Know (But Most Ignore)

Medium Programming • 47m ago

The Deceptively Tricky Art of Designing a Steering Wheel
How-To

The Deceptively Tricky Art of Designing a Steering Wheel

Wired • 1h ago

7 Wireshark Filters That Instantly Make You Look Like a Network Expert
How-To

7 Wireshark Filters That Instantly Make You Look Like a Network Expert

Medium Programming • 2h ago

Week 6 — No New Problems. Just Me and Everything I Already Learned.
How-To

Week 6 — No New Problems. Just Me and Everything I Already Learned.

Medium Programming • 7h ago

What OpenClaw Gets Wrong Out of the Box (And How to Fix It)
How-To

What OpenClaw Gets Wrong Out of the Box (And How to Fix It)

Medium Programming • 8h ago

Discover More Articles