Medium severity5.3NVD Advisory· Published Aug 19, 2025· Updated Jun 17, 2026
CVE-2025-50579
CVE-2025-50579
Description
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and exfiltrate them to a remote attacker-controlled server, potentially leading to unauthorized actions within the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Nginx/Nginx Proxy Managerdescription
- Range: <=2.12.3
Patches
Vulnerability mechanics
References
1- github.com/NginxProxyManager/nginx-proxy-manager/issues/4509nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.