CVE-2026-27818

HIGH

TerriaJS-Server <4.0.3 - SSRF

Title source: llm
STIX 2.1

Description

TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.

Scores

CVSS v3 7.5
EPSS 0.0010
EPSS Percentile 27.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-918
Status published
Products (2)
npm/terriajs-server 0 - 4.0.3npm
terria/terriajs-server < 4.0.3
Published Feb 26, 2026
Tracked Since Feb 26, 2026