Security guidance for vibe apps
CORS is a browser boundary, not authentication
CORS decides which website may read browser responses. `Access-Control-Allow-Origin: *` can suit public data but not private APIs or credentialed requests.
Reviewed by René Matis · MATIS LABS · Updated 15 August 2026
The scan is free and takes about twenty seconds. You see straight away how many findings there are and how serious they are.
Scan your own app for freeHow to recognise the problem
Dangerous cases include reflected origins without an allowlist, wildcards on private APIs and origin-dependent responses without correct `Vary: Origin`.
A working happy path does not prove this boundary. Always test with a second user, while signed out or with an intentionally forbidden input.
How to fix it reliably
Allow exact production origins only, validate them strictly and set `Vary: Origin` when responses differ by origin.
The control belongs at the server-side trust boundary. A hidden button, different client copy or browser-only validation is not a security control.
Re-test instead of hoping
MLVibeScan checks runtime headers and Node, Vercel, Netlify and nginx configuration. A re-test compares the stable protection target with the previous result and reports fixed, partially fixed, unchanged or regression.
Automated checks cover recurring patterns. High-risk business logic may additionally require an individually scoped penetration test.
What we check automatically
- runtime headers and Node, Vercel, Netlify and nginx configuration
- Confidence and counter-checking
- Stable fingerprints for re-tests
Frequently asked questions
- Can this be tested from the outside?
- Partly. MLVibeScan checks runtime headers and Node, Vercel, Netlify and nginx configuration; source and deep checks require purchase, domain verification and explicit consent.
- Is blocking access in the UI enough?
- No. Security decisions must be enforced server-side for every request, regardless of the client an attacker uses.
- When is the finding fixed?
- Only when the control holds in a controlled re-test and no contradictory source/runtime observation remains.