VDB
Sign up
HIGH

GHSA-mm7r-265w-jv6f

Server-Side Request Forgery in @uppy/companion

Quick fix

GHSA-mm7r-265w-jv6f — @uppy/companion: upgrade to the fixed version with the command below.

npm install @uppy/companion@1.9.3

Details

Versions of `@uppy/companion` prior to 1.9.3 are vulnerable to Server-Side Request Forgery (SSRF). The `get` route passes the user-controlled variable `req.body.url` to a GET request without sanitizing the value. This allows attackers to inject arbitrary URLs and make GET requests on behalf of the server.

## Recommendation

Upgrade to version 1.9.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@uppy/companion
Introduced in: 0Fixed in: 1.9.3
Fixnpm install @uppy/companion@1.9.3

References