Permissive origin in postMessage detected.


Using "*" (any) as the target origin of a postMessage call allows third-parties to read the message.


❌ Avoid using "*" as the target origin:

window.postMessage(message, '*')

✅ Specify the origin for your target application:

window.postMessage(message, '')

Associated CWE

Ready to take the next step? Join the Bearer Cloud waitlist.