Checks

CORS allows any origin

Access-Control-Allow-Origin is *.

Why it matters

Any website can read this response from a browser. That is fine for a truly public asset and risky for anything user-specific.

What to do

Restrict the header to trusted origins if the body is not public.

Reference

CORS controls which origins may read responses and must not expose credentialed data broadly.

MDN — Cross-Origin Resource Sharing (CORS)