PT-2026-22060 · Unknown · Terriajs-Server

Peter Hassall

·

Published

2026-02-26

·

Updated

2026-03-04

·

CVE-2026-27818

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TerriaJS-Server versions prior to 4.0.3
Description A validation flaw permits an attacker to proxy domains not explicitly listed in the proxyableDomains configuration. The validation process only verifies if a hostname ends with an allowed domain, which allows malicious domains to be proxied through the server. For example, if example.com is in proxyableDomains, maliciousexample.com could also be proxied. This bypasses proxy restrictions.
Recommendations Upgrade to version 4.0.3 to resolve the issue.

Exploit

Fix

RCE

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-27818
GHSA-W789-49FC-V8HR

Affected Products

Terriajs-Server