⚠ CORS Vulnerability — Teramind Identity Token Theft

This page demonstrates that any *teramind.co domain can steal authenticated identity tokens from Teramind users via a CORS misconfiguration.

⚡ To reproduce: Visit this page while logged into any Teramind instance, then click "Run PoC". Your identity tokens will be stolen and displayed below — exactly as an attacker would see them.

⚙ Configuration

🎯 Stolen: Intercom + ChurnZero Identity Tokens

⏳ Waiting — click "Run PoC" to start

🔑 Stolen: Teramind Internal Identity JWT

⏳ Waiting — click "Run PoC" to start

📋 Attack Summary

Waiting for PoC to run...