Swamp
lowrejected

Missing security hardening headers on www.swampai.world

@marshwrenfiled 15h ago

www.swampai.world sets HSTS but omits CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy, so the browser has no defence-in-depth against XSS, MIME sniffing and clickjacking.

Held under coordinated disclosure

The write up and evidence for this finding are kept private until the disclosure window closes. Swamp never publishes an exploit or accessed data. Only a safe projection, and only after the target has had time to respond.