Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CorsMe — Cross Origin Resource Sharing MisConfiguration Scanner | Kitploit
Tools/GitHubGitHub/shivangx01b/corsme
Vulnerability ScannersWeb SecurityPenetration TestingMisconfiguration
GitHubshivangx01b/corsme

CorsMe

Cross Origin Resource Sharing MisConfiguration Scanner

View Repository
170265 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share



What is CorsMe ?

A cors misconfiguration scanner tool based on golang with speed and precision in mind !

Misconfiguration type this scanner can check for

  • Reflect Origin checks
  • Prefix Match
  • Suffix Match
  • Not Esacped Dots
  • Null
  • ThirdParties (Like => github.io, repl.it etc.)
    • Taken from Chenjj's github repo
  • SpecialChars (Like => "}","(", etc.)
    • See more in Advanced CORS Exploitation Techniques

How to Install

root@kitploit:~
$ go get -u -v github.com/shivangx01b/CorsMe

Usage

Single Url

root@kitploit:~
echo "https://example.com" | ./CorsMe 

Multiple Url

root@kitploit:~
cat http_https.txt | ./CorsMe -t 70

Allow wildcard .. Now if Access-Control-Allow-Origin is * it will be printed

root@kitploit:~
cat http_https.txt | ./CorsMe -t 70 -wildcard

Add header if required

root@kitploit:~
cat http_https.txt | ./CorsMe -t 70 -wildcard -header "Cookie: Session=12cbcx...."

Save output in a file

root@kitploit:~
cat http_https.txt | ./CorsMe -t 70 -output audit.logs

Add another method if required

root@kitploit:~
cat http_https.txt | ./CorsMe -t 70 -wildcard -header "Cookie: Session=12cbcx...." -method "POST"

Tip

root@kitploit:~
subfinder -d hackerone.com -nW -silent | ./httprobe -c 70 -p 80,443,8080,8081,8089 | tee http_https.txt
cat http_https.txt | ./CorsMe -t 70

Screenshot

1414

Note:

  • Scanner stores the error results as "error_requests.txt"... which contains hosts which cannot be requested

Ideas for making this tool are taken from :

CORScanner

Corsy

cors-blimey

Download Tool