GHSA-w789-49fc-v8hr
TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist
Quick fix
GHSA-w789-49fc-v8hr — terriajs-server: upgrade to the fixed version with the command below.
npm install terriajs-server@4.0.3Details
### Impact A validation bug allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration.
The validation only checks if a hostname _ended_ with an allowed domain. This meant:
If `example.com` is allowed in `proxyableDomains`:
- ✅ example.com is allowed (correct) - ✅ api.example.com is allowed (correct) - ⚠️ maliciousexample.com is allowed (incorrect)
An attacker could register maliciousexample.com and proxy content through `terriajs-server`, bypassing proxy restrictions.
### Patches All versions up to 4.0.2 are affected. Upgrade to 4.0.3 to address the vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/TerriaJS/terriajs-server/security/advisories/GHSA-w789-49fc-v8hr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-27818[ADVISORY]
- https://github.com/TerriaJS/terriajs-server/commit/3aaa5d9717162b245ae4569232bbe7d8673c913f[WEB]
- https://github.com/TerriaJS/terriajs-server[PACKAGE]
- https://github.com/TerriaJS/terriajs-server/releases/tag/4.0.3[WEB]