Disabled Helmet protections (frameguard/xFrameOptions/CSP)

Insecure security headers (Helmet misconfiguration)

Description

Helmet sets security HTTP headers for Express applications. Depending on the version, its framing option may be named frameguard or xFrameOptions. Setting a header option such as this or contentSecurityPolicy (CSP) to false stops Helmet from providing that header. Without equivalent policies elsewhere, this can weaken defenses against clickjacking or script injection. Disabling CSP does not create XSS on its own.

Potential impact

  • Without framing restrictions, an attacker may embed a page in an iframe and trick users into clicking unintended actions.
  • Without an effective CSP, fewer restrictions limit malicious script loading and execution if a script injection vulnerability exists.

Remediation

  • Keep the default protections from app.use(helmet()) where possible. Check the headers actually returned by the application or proxy.
  • Restrict framing origins with X-Frame-Options or CSP's frame-ancestors, using options appropriate for your Helmet version. Their protections overlap, so evaluate the policies together in the final response.
  • Limit CSP to required sources. Where needed, use nonce- or hash-based policies instead of broad *, 'unsafe-inline', or 'unsafe-eval' allowances.
  • Apply exceptions only to pages that need external frames or scripts.

Examples

Before

javascript
const express = require("express");
const helmet = require("helmet");
const app = express();

// Before: disable both framing headers and CSP in this middleware.
app.use(helmet({
  xFrameOptions: false,
  contentSecurityPolicy: false,
}));

app.get("/pay", (req, res) => {
  res.send('<button id="pay">결제하기</button>');
});

app.listen(3000);

After

javascript
const express = require("express");
const helmet = require("helmet");
const app = express();

// After: enable Helmet with restrictive CSP and framing policies.
app.use(
  helmet({
    // Older Helmet versions use frameguard: { action: "sameorigin" }.
    xFrameOptions: { action: "sameorigin" },
    contentSecurityPolicy: {
      useDefaults: true,
      directives: {
        "default-src": ["'self'"],
        "script-src": ["'self'"], // Disallow inline scripts and arbitrary external sources.
        "object-src": ["'none'"],
        "frame-ancestors": ["'self'"], // Restrict framing origins.
      },
    },
  })
);

app.get("/pay", (req, res) => {
  res.send('<button id="pay">결제하기</button>');
});

app.listen(3000);

Explanation:

  • Before: One Helmet configuration disables both X-Frame-Options and CSP. Both headers are absent unless another layer provides them.
  • After: Policies allow only same-origin frames and scripts. Adjust them to the service's requirements and Helmet version.

References