GHSA-7899-w6c4-vqc4
@misskey-dev/summaly Redirect Filter Bypass
Quick fix
GHSA-7899-w6c4-vqc4 — @misskey-dev/summaly: upgrade to the fixed version with the command below.
npm install @misskey-dev/summaly@5.2.1Details
### Summary A logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced.
### Details In the main `summaly` function, a new `scrapingOptions` object is created and passed to either the matched plugin, if any, or the default summarize function. The issue here is that the new `scrapingOptions` object is not provided the `allowRedirects` property of `opts`.
### PoC - Publish a post containing a link to any URL that redirects on Misskey. - A preview will be generated for the target of the redirect, despite Misskey passing `allowRedirects: false`.
### Impact Misskey will follow redirects, despite explicitly requesting not to.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.0.1Fixed in: 5.2.1npm install @misskey-dev/summaly@5.2.1