HIGH
GHSA-mm7r-265w-jv6f
Server-Side Request Forgery in @uppy/companion
Quick fix
GHSA-mm7r-265w-jv6f — @uppy/companion: upgrade to the fixed version with the command below.
npm install @uppy/companion@1.9.3Details
Versions of `@uppy/companion` prior to 1.9.3 are vulnerable to Server-Side Request Forgery (SSRF). The `get` route passes the user-controlled variable `req.body.url` to a GET request without sanitizing the value. This allows attackers to inject arbitrary URLs and make GET requests on behalf of the server.
## Recommendation
Upgrade to version 1.9.3 or later.
Are you affected?
Enter the version of the package you're using.