Content-Security-Policy allows scripts from any origin
Evidence
GET https://app.example.com/ → 200 OK
content-type: text/html; charset=utf-8
content-security-policy: default-src 'self'; script-src 'self' *; object-src 'none'How to fix it
List the origins your pages really load scripts from (your own domain, your analytics or payment provider). Replace the wildcard in script-src with those origins, for example: script-src 'self' https://js.stripe.com Deploy it first as Content-Security-Policy-Report-Only if you are unsure, and watch for violations. Switch to the enforcing header and re-test the finding from your report.