A validation bug allows an attacker to proxy domains not explicitly allowed in the proxyableDomains configuration.
The validation only checks if a hostname ended with an allowed domain. This meant:
If example.com is allowed in proxyableDomains:
An attacker could register maliciousexample.com and proxy content through terriajs-server, bypassing proxy restrictions.
All versions up to 4.0.2 are affected. Upgrade to 4.0.3 to address the vulnerability.
| Score | Percentile |
|---|---|
| 0.10% | 28.33% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 8.7 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-w789-49fc-v8hr ↗ |
| CVE | CVE-2026-27818 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | terriajs-server | < 4.0.3 | 4.0.3 | — |