Vulnerabilities (CVE)

Filtered by vendor Terria Subscribe
Filtered by product Terriajs-server
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-27818 1 Terria 1 Terriajs-server 2026-03-04 N/A 7.5 HIGH
TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.